Junglewise Threat Intelligence

CVE-2026-46785: Oracle WebCenter Content CSRF in Content Server

CVE-2026-46785 · Severity: critical · CVSS 9.3 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, contains a critical security vulnerability. An attacker can trick a legitimate user into performing unintended actions, potentially leading to the total compromise of sensitive business data. This could result in the unauthorized viewing, modification, or deletion of critical company records and may impact other integrated systems.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Content Server component of Oracle WebCenter Content version 14.1.2.0.0. The flaw is easily exploitable by an unauthenticated remote attacker via HTTP, though it requires interaction from a victim (User Interaction: Required). Because the vulnerability involves a scope change (Scope: Changed), an exploit can impact products beyond the immediate component. A successful attack grants the adversary full confidentiality and integrity impacts, allowing for the unauthorized creation, deletion, or modification of all data accessible to the compromised session.

Affected products

  • Oracle WebCenter Content 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References

Related threats