External risk intelligence

Oracle WebCenter Content Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-60644

Oracle WebCenter Content is a middleware platform used for enterprise web content management. These systems are frequently deployed as internet-facing web applications or portals to facilitate content access and management, making them reachable via HTTP from the network.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle WebCenter Content, a component of Oracle Fusion Middleware. This issue, which can be exploited remotely without authentication, could allow an attacker to gain complete control of the affected systems. The potential impact extends beyond the immediate product, as successful attacks may affect other connected products.

  • Unauthenticated attackers can control WebCenter Content.
  • This could impact critical business content management.
  • Verify if this Oracle product is in use.

Attack Path

How an attacker could exploit the issue

An attacker could reach Oracle WebCenter Content over the network, even without authentication. The vulnerability resides within the Web Content Management component, and if successfully exploited, could lead to a complete takeover of the WebCenter Content system, potentially impacting other connected products.

  • Unauthenticated network access required.
  • Exploits Web Content Management.
  • Enables full system takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access could compromise Oracle WebCenter Content, potentially impacting other connected products. Successful attacks could lead to a complete takeover of the Oracle WebCenter Content system, affecting its confidentiality, integrity, and availability.

  • Oracle WebCenter Content system data.
  • Network access via HTTP.
  • Takeover of the affected system.

Operational Fix

Recommended remediation, mitigation, and detection steps

Oracle WebCenter Content, a component within Oracle Fusion Middleware, is susceptible to an unauthenticated network attack. This vulnerability, impacting specific supported versions, can lead to a complete takeover of the product and potentially affect other integrated Oracle products. Initial steps should focus on identifying deployments, assessing exposure and criticality, and locating the accountable owner to plan a risk-based remediation.

  • Identify application and infrastructure owners.
  • Verify reachability and criticality of instances.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle WebCenter Content?

Oracle WebCenter Content is a middleware platform within the Oracle Fusion Middleware family. It serves as an enterprise-grade system for managing web content, documents, and digital assets. Organizations typically use it to store, organize, and serve content across their web portals and business applications, acting as a central repository for critical information that requires secure management.

How does CVE-2026-60644 work?

This vulnerability is a flaw in the Web Content Management component of the software. It allows an attacker to manipulate the system remotely. Because it involves a complete system takeover, it is classified as a critical weakness that compromises the confidentiality, integrity, and availability of all data managed by the application. The issue is severe because it gives an attacker full control over the platform's functions.

Do I need to be authenticated to trigger CVE-2026-60644?

No. The vulnerability is designed such that an attacker does not need any valid login credentials or prior authorization to initiate an attack. The exploit is triggered simply by sending specific requests over the network via HTTP. If the attacker has network access to the affected Oracle WebCenter Content instance, they can attempt the exploit without being a known user of the system.

Is my Oracle WebCenter Content instance at risk?

If your instance is reachable via the internet, it is at higher risk because the vulnerability is exploitable over the network without authentication. According to Halo Surface Signal, Oracle WebCenter Content is frequently deployed as an internet-facing web application to facilitate content access. Even if your instance is internal, any attacker who has gained a foothold on your internal network could potentially reach and exploit this vulnerability.

What should I do to secure my environment?

Begin by identifying all deployments of Oracle WebCenter Content within your infrastructure and confirm if you are running versions 12.2.1.4.0 or 14.1.2.0.0. Once identified, document which instances are internet-facing versus internal to help prioritize them. Coordinate with the relevant application and infrastructure owners to assess the business criticality of each instance, then follow official guidance from Oracle to apply the necessary security updates.

References