Executive brief
Oracle WebCenter Content is a platform used by organizations to manage and share business documents and digital assets. A critical security vulnerability has been identified that allows an unauthorized person to take complete control of the system over the internet. This could lead to the theft of sensitive corporate data, loss of service availability, and unauthorized modification of business records.
Technical details
A vulnerability classified as Improper Access Control (CWE-284) exists in the Content Server component of Oracle WebCenter Content. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows for a complete takeover of the affected Oracle WebCenter Content instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory