Executive brief
Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a security vulnerability in its Content Server component. An attacker with basic user credentials can exploit this flaw over the network to gain full control of the system. This could lead to the unauthorized access, modification, or deletion of sensitive corporate documents and a total disruption of the content management service.
Technical details
A vulnerability in the Content Server component of Oracle WebCenter Content (part of Oracle Fusion Middleware) is classified as improper access control (CWE-284). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to compromise the integrity, confidentiality, and availability of the application, potentially resulting in a complete takeover of the WebCenter Content instance. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. Users are advised to consult the Oracle Critical Patch Update for remediation steps.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD record published