Junglewise Threat Intelligence

CVE-2026-46766: Oracle WebCenter Content improper access control in Content Server

CVE-2026-46766 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content is a document management platform used by organizations to store and manage corporate records and digital assets. A critical vulnerability in the Content Server component allows an unauthorized person to gain full control over the system via the internet. This could lead to the theft of sensitive documents, data destruction, or a complete shutdown of the document management service.

Technical details

This vulnerability (CWE-284) exists in the Content Server component of Oracle WebCenter Content. It is categorized as an improper access control issue that is easily exploitable over the network via HTTP without requiring any user interaction or prior authentication. A successful exploit allows a remote attacker to achieve a complete takeover of the affected Oracle WebCenter Content instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats