CVE-2026-60644: Critical severity Oracle Oracle WebCenter Content vulnerability
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60644?
CVE-2026-60644 has a critical severity rating of 10.
How do I fix CVE-2026-60644?
To remediate CVE-2026-60644, it is crucial to apply the latest security patch provided by Oracle for affected versions.
What types of attacks are possible with CVE-2026-60644?
CVE-2026-60644 allows unauthenticated attackers to exploit the vulnerability via HTTP network access.
Which versions of Oracle WebCenter Content are affected by CVE-2026-60644?
Affected versions of Oracle WebCenter Content include 12.2.1.4.0 and 14.1.2.0.0.
What component of Oracle Fusion Middleware does CVE-2026-60644 impact?
CVE-2026-60644 impacts the Web Content Management component of Oracle WebCenter Content.