Executive brief
A vulnerability in Oracle WebCenter Content, a document management platform, allows an attacker with low-level access to compromise the system. By tricking another user into performing an action, an attacker can gain unauthorized access to sensitive corporate data or modify existing records. This could lead to significant data breaches or the corruption of business-critical documents.
Technical details
This vulnerability exists in the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0). It is classified as an improper access control issue (CWE-284) that is easily exploitable by a low-privileged attacker with network access via HTTPS. The attack requires human interaction from a victim (UI:R) and involves a scope change (S:C), suggesting it may be a Cross-Site Scripting (XSS) or similar injection flaw that allows the attacker to impact other products or the underlying security posture. Successful exploitation can result in unauthorized read access to all data or unauthorized update/delete access to a subset of data.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published