External risk intelligence

Oracle WebCenter Content Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60435

Oracle WebCenter Content is a middleware application that often functions as an internet-facing or externally reachable content management system, and the vulnerability is accessible via unauthenticated HTTP network requests.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle WebCenter Content, a component of Oracle Fusion Middleware. This issue could allow an attacker to gain complete control over the affected system without authentication, potentially impacting the availability and integrity of managed content. The primary concern at this time is to determine if your organization utilizes this specific Oracle product.

  • Unauthenticated attackers can fully control the product.
  • Matters because it affects critical content management.
  • Verify if this Oracle product is in use.

Attack Path

How an attacker could exploit the issue

An attacker can target Oracle WebCenter Content by sending specially crafted network requests over HTTP. Since no authentication is required, an unauthenticated attacker can exploit this vulnerability to gain complete control over the WebCenter Content system.

  • Network access required.
  • HTTP requests trigger vulnerability.
  • Full system takeover possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could impact Oracle WebCenter Content, potentially allowing an attacker to gain complete control over the system. The attacker could exploit this through network access via HTTP without needing any authentication.

  • Oracle WebCenter Content system.
  • Unauthenticated network access via HTTP.
  • Takeover of Oracle WebCenter Content.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Oracle WebCenter Content, accessible via unauthenticated network requests, likely requires coordination between application owners, infrastructure teams, and security operations to identify and mitigate. The first step is to determine the scope of affected systems, their business criticality, and the responsible parties.

  • Application owners should confirm asset inventory.
  • Verify network exposure and business criticality.
  • Plan remediation based on risk and impact.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle WebCenter Content?

Oracle WebCenter Content is a middleware application within the Oracle Fusion Middleware suite. It serves as a comprehensive content management system, helping organizations store, manage, and distribute enterprise documents and digital assets. It acts as a central repository that teams rely on to handle business-critical information and workflows.

How does CVE-2026-60435 affect the software?

This vulnerability represents a critical security flaw that allows an unauthorized party to bypass authentication mechanisms. By sending specially crafted HTTP requests to the Content Server, an attacker can gain full control over the system. This type of weakness effectively removes the gatekeeping that should protect the application, allowing an external actor to perform actions as if they were an authorized administrator.

Can any network request trigger this vulnerability?

No. While the vulnerability is triggered via HTTP, it requires specific, maliciously crafted requests to succeed. The bug is not triggered by standard, legitimate user interactions or typical browsing activity. The attacker must have the ability to send these targeted, unauthorized requests directly to the Oracle WebCenter Content service.

Do I need to worry if my system is internal?

You should investigate your environment regardless of placement. While Halo Surface Signal notes that Oracle WebCenter Content often functions as an internet-facing system, which significantly increases risk, the vulnerability also poses a threat to internal systems. If an attacker gains a foothold on your internal network, they could leverage this vulnerability to pivot and compromise the content management system from the inside.

What should I do first to address this issue?

Your immediate priority is visibility. Coordinate with your application and infrastructure teams to confirm whether you have any instances of Oracle WebCenter Content running versions 12.2.1.4.0 or 14.1.2.0.0. Once identified, document which systems are mission-critical and determine if those systems are reachable over a network. This inventory is the necessary foundation for planning your security response and applying vendor-provided updates.

References