Oracle WebCenter Sites: data exposure via WebCenter Sites
High8.6CVE-2026-60556 · Published Jul 21, 2026 · updated Jul 30, 2026
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Oracle WebCenter Sites Product | <= 12.2.1.4.0 | No fix yet |
| <= 14.1.2.0.0 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-200
More Oracle advisories
All Oracle| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 21 | Oracle HRMS (US): takeover via Internal Operations | High7.8 | No fix yet |
| Jul 21 | Oracle HRMS (US): data exposure via Internal Operations | Medium6.5 | No fix yet |
| Jul 21 | Oracle Work in Process: data tampering via Internal Operations | Medium5.4 | No fix yet |
| Jul 21 | Oracle HRMS (US): data tampering via US Payroll Year End | High7.1 | No fix yet |
| Jul 21 | Oracle HRMS (UK): data exposure via UK Payroll | High7.7 | No fix yet |
| Jul 21 | Oracle Java SE: takeover via Install | High7.8 | No fix yet |