CVE-2026-60961: High severity Oracle Oracle WebCenter Content vulnerability
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle WebCenter Content executes to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Exposure is limited to deployments running Oracle WebCenter Content Content Server version 12.2.1.4.0 or 14.1.2.0.0 where an attacker can access the physical communication segment connected to the hardware hosting the product. The attack does not require authentication or user interaction.
What level of access does an attacker need to exploit it?
An attacker needs adjacent-network access: access to the physical communication segment attached to the hardware where Oracle WebCenter Content runs. Exploitation is rated difficult and does not require prior privileges.
What could indicate that a system has been affected?
Potential indicators include unauthorized creation, deletion, or modification of critical data or other data accessible to Oracle WebCenter Content, as well as unauthorized access to that data. Because the issue can affect additional products through scope change, investigate related systems that may have been significantly impacted by a compromise.