PatchSiren cyber security CVE debrief
CVE-2026-60335 Oracle Corporation CVE debrief
The CVE-2026-60335 vulnerability affects Oracle WebCenter Content, specifically versions 12.2.1.4.0 and 14.1.2.0.0. This is an easily exploitable vulnerability that allows high privileged attackers with network access via HTTP to compromise the system, potentially leading to takeover. The CVSS 3.1 Base Score is 7.2, indicating high severity. Users and administrators should prioritize patching and assess exposure. The NVD entry is currently Undergoing Analysis, and evidence is limited to vendor statements.
- Vendor
- Oracle Corporation
- Product
- Oracle WebCenter Content
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-08-07
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-08-07
Who should care
Users of Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 should prioritize patching. Security teams and administrators managing Oracle products must assess exposure and apply mitigations. Vulnerability management and incident response teams should monitor for potential exploitation attempts. Operators of affected systems should review the official advisory and take necessary actions to protect their environments.
Technical summary
The vulnerability in Oracle WebCenter Content allows high privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in takeover. The affected versions are 12.2.1.4.0 and 14.1.2.0.0. The CVSS 3.1 Base Score is 7.2, with impacts on Confidentiality, Integrity, and Availability. Defenders should verify system configurations and apply patches when available.
Defensive priority
High privileged attackers with network access via HTTP can compromise Oracle WebCenter Content, potentially leading to takeover.
Recommended defensive actions
- Inventory and verify Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are not in use
- Apply vendor remediation when available
- Monitor for suspicious activity
- Implement compensating controls
- Exception tracking and retest
- Review relevant logs for exposed assets
- Track exceptions and retest remediated assets
Evidence notes
The CVE is based on information from Oracle's security alert for July 2026. The vulnerability affects Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0. Evidence is limited to vendor statements and may not reflect real-world attacks or exploits. Defenders should verify system configurations and apply patches when available. Additional information may be found in Oracle's official advisory.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-60335 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-60335
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-60335 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60335
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cpujul2026.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.