CVE-2026-60658: CSRF
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60658?
The severity of CVE-2026-60658 is rated high with a CVSS score of 7.5.
How do I fix CVE-2026-60658?
To fix CVE-2026-60658, you should update to the latest patched version of Oracle WebCenter Content as provided by Oracle.
What types of attacks can CVE-2026-60658 be exploited by?
CVE-2026-60658 can be exploited by unauthenticated attackers with network access via HTTP.
Which versions of Oracle WebCenter Content are affected by CVE-2026-60658?
The affected versions of Oracle WebCenter Content are 12.2.1.4.0 and 14.1.2.0.0.
What is the nature of the vulnerability described in CVE-2026-60658?
CVE-2026-60658 is a Cross-Site Request Forgery (CSRF) vulnerability that can be difficult to exploit.