Executive brief
Oracle WebCenter Content is a platform used by organizations to manage and share business documents and digital assets. A vulnerability in the Content Server component allows an attacker with basic user credentials to gain full control over the system via the network. This could lead to the unauthorized access, modification, or deletion of sensitive corporate documents and a total disruption of the content management service.
Technical details
This vulnerability is classified as Improper Access Control (CWE-284) within the Content Server component of Oracle WebCenter Content. It is easily exploitable by a low-privileged attacker who has network access via HTTP. The flaw does not require user interaction and has a high impact on confidentiality, integrity, and availability, effectively allowing for a total system takeover. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation details.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD record published