Summary
CVE-2026-60935 is a vulnerability in the Content Server component of Oracle WebCenter Content (Oracle Fusion Middleware) that allows an unauthenticated, network-based attacker over HTTP to gain unauthorized access to, or modify/delete, data managed by the application. Oracle rates exploitation as difficult, but a successful attack can affect data and resources beyond the vulnerable component itself. The issue was disclosed and patched in Oracle’s August 2026 Critical Patch Update, and carries a HIGH severity rating.
Technical details
- Root cause: Oracle’s advisory does not disclose the specific technical weakness; the flaw resides in the Content Server component of WebCenter Content.
- Trigger conditions: Exploitable remotely over HTTP without authentication or user interaction, though Oracle classifies exploitation as difficult (high attack complexity).
- Attack vector: Network (AV:N) — no privileges or user interaction required.
- Impact: Unauthorized creation, deletion, or modification of critical data, potentially extending to all data accessible to WebCenter Content. The CVSS vector’s Scope Changed (S:C) designation indicates impact can extend to components beyond WebCenter Content itself. No impact on availability.
Affected software
- Oracle WebCenter Content (Oracle Fusion Middleware, Content Server component) version 12.2.1.4.0
- Oracle WebCenter Content (Oracle Fusion Middleware, Content Server component) version 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 8.7 (High)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Patch Update released in August 2026, which contains the fix for CVE-2026-60935, to all affected Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 deployments.
- If patching cannot be applied immediately: Restrict and monitor network access to WebCenter Content HTTP endpoints (e.g., via firewalls, VPN, or access control lists) to limit exposure to trusted networks, and monitor for anomalous or unexpected content creation/modification/deletion activity until the patch can be applied.

