CVE-2026-60664: XSS
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60664?
CVE-2026-60664 has a severity rating of 8.8, which is categorized as high.
How do I fix CVE-2026-60664?
To fix CVE-2026-60664, it is recommended to apply the latest security patches provided by Oracle for affected versions.
What components are affected by CVE-2026-60664?
CVE-2026-60664 affects the Content Server component of the Oracle WebCenter Content product within Oracle Fusion Middleware.
Can CVE-2026-60664 be exploited remotely?
Yes, CVE-2026-60664 is easily exploitable by an unauthenticated attacker with network access via HTTP.
Which specific versions of Oracle WebCenter Content are vulnerable to CVE-2026-60664?
The affected versions for CVE-2026-60664 are 12.2.1.4.0 and 14.1.2.0.0.