Executive brief
A critical vulnerability exists in Oracle WebCenter Content, a platform used for managing corporate documents and digital assets. A user with low-level access can exploit this flaw over the network to take full control of the system. This could lead to the theft of sensitive business data, unauthorized modification of records, or a complete shutdown of the content management service.
Technical details
An improper access control vulnerability (CWE-284) exists in the Content Server component of Oracle WebCenter Content. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. A successful exploit results in a 'scope change' (S:C), meaning the attacker can move beyond the WebCenter Content environment to impact additional integrated products. This can lead to a total takeover of the affected system, compromising confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Security Alert published