Summary
CVE-2026-60954 is a vulnerability in the Content Server component of Oracle WebCenter Content that allows an unauthenticated attacker with network access via HTTP to compromise the system, resulting in unauthorized creation, deletion, or modification of critical data. Oracle rates the flaw High severity (CVSS 8.7) and notes it may also impact additional Oracle products beyond WebCenter Content itself. It was disclosed as part of Oracle’s August 2026 Critical Patch Update.
Technical details
- Root cause: Improper access control in the Content Server component of Oracle WebCenter Content, permitting unauthorized creation, deletion, or modification of data that should require authorization.
- Trigger conditions: Oracle describes the flaw as difficult to exploit, requiring specific conditions/configuration knowledge beyond simply having network access (reflected in a High Attack Complexity rating).
- Attack vector: Network — the vulnerability is exploitable remotely over HTTP without authentication and without user interaction.
- Impact: Successful exploitation compromises confidentiality and integrity of data managed by the Content Server (unauthorized read/write/delete of critical data); no direct availability impact is scored. The CVSS Scope is rated "Changed," indicating impact can extend beyond the vulnerable component.
Affected software
- Oracle WebCenter Content 12.2.1.4.0
- Oracle WebCenter Content 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 8.7 (High)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Patch Update for August 2026, which contains the fix for CVE-2026-60954 in Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0. Oracle states security patches must be applied as it will not release standalone patches for this vulnerability outside the CPU.
- If immediate patching is not possible: Restrict network exposure of WebCenter Content Server (e.g., place it behind a firewall/VPN and limit access to trusted internal networks) and monitor Content Server logs for unexpected content creation, deletion, or modification activity until the CPU can be applied.

