{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-60658",
        "assignerOrgId": "43595867-4340-4103-b7a2-9a5208d29a85",
        "state": "PUBLISHED",
        "assignerShortName": "oracle",
        "dateReserved": "2026-07-08T15:51:55.575Z",
        "datePublished": "2026-07-21T21:36:25.201Z",
        "dateUpdated": "2026-07-28T03:56:50.771Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "43595867-4340-4103-b7a2-9a5208d29a85",
                "shortName": "oracle",
                "dateUpdated": "2026-07-21T21:36:25.201Z"
            },
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en-US",
                            "description": "Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Oracle Corporation",
                    "product": "Oracle WebCenter Content",
                    "versions": [
                        {
                            "version": "12.2.1.4.0",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "14.1.2.0.0",
                            "status": "affected",
                            "versionType": "semver"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*"
                                }
                            ]
                        }
                    ]
                }
            ],
            "descriptions": [
                {
                    "lang": "en-US",
                    "value": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)."
                }
            ],
            "references": [
                {
                    "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
                    "name": "Oracle Advisory",
                    "tags": [
                        "vendor-advisory"
                    ]
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "attackVector": "NETWORK",
                        "attackComplexity": "HIGH",
                        "privilegesRequired": "NONE",
                        "userInteraction": "REQUIRED",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "HIGH",
                        "availabilityImpact": "HIGH",
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    }
                }
            ]
        },
        "adp": [
            {
                "problemTypes": [
                    {
                        "descriptions": [
                            {
                                "type": "CWE",
                                "cweId": "CWE-601",
                                "lang": "en",
                                "description": "CWE-601 URL Redirection to Untrusted Site ('Open Redirect')"
                            }
                        ]
                    },
                    {
                        "descriptions": [
                            {
                                "type": "CWE",
                                "cweId": "CWE-640",
                                "lang": "en",
                                "description": "CWE-640 Weak Password Recovery Mechanism for Forgotten Password"
                            }
                        ]
                    },
                    {
                        "descriptions": [
                            {
                                "type": "CWE",
                                "cweId": "CWE-352",
                                "lang": "en",
                                "description": "CWE-352 Cross-Site Request Forgery (CSRF)"
                            }
                        ]
                    },
                    {
                        "descriptions": [
                            {
                                "type": "CWE",
                                "cweId": "CWE-451",
                                "lang": "en",
                                "description": "CWE-451 User Interface (UI) Misrepresentation of Critical Information"
                            }
                        ]
                    }
                ],
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-07-27T00:00:00+00:00",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3",
                                "id": "CVE-2026-60658"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-07-28T03:56:50.771Z"
                }
            }
        ]
    }
}