CVE-2026-60646: XSS
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60646?
The severity of CVE-2026-60646 is rated high with a score of 8.
What types of attacks can exploit CVE-2026-60646?
CVE-2026-60646 can be exploited through XSS and CSRF attack vectors.
How do I fix CVE-2026-60646?
To fix CVE-2026-60646, users should apply the latest patches or updates provided by Oracle for affected versions.
Which versions of Oracle WebCenter Content are affected by CVE-2026-60646?
The affected versions of Oracle WebCenter Content include 12.2.1.4.0 and 14.1.2.0.0.
What is the impact of exploiting CVE-2026-60646?
Exploiting CVE-2026-60646 allows a low privileged attacker with network access to compromise the affected Oracle WebCenter Content systems.