Executive brief
Oracle WebCenter Content is a document management platform used by organizations to store and manage corporate records and digital assets. A critical vulnerability in the Content Server component allows an unauthorized person to gain full control over the system via the internet. This could lead to the theft of sensitive documents, data destruction, or a complete shutdown of the document management service.
Technical details
This vulnerability (CWE-284) exists in the Content Server component of Oracle WebCenter Content. It is categorized as an improper access control issue that is easily exploitable over the network via HTTP without requiring any user interaction or prior authentication. A successful exploit allows a remote attacker to achieve a complete takeover of the affected Oracle WebCenter Content instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory