Junglewise Threat Intelligence

CVE-2026-46786: Oracle WebCenter Content CSRF in Content Server

CVE-2026-46786 · Severity: critical · CVSS 9.6 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content is a platform used by organizations to manage and share business documents and digital assets. A critical vulnerability has been identified that allows an unauthorized person to take full control of the system if a legitimate user is tricked into performing a specific action, such as clicking a malicious link. This could lead to the theft of sensitive corporate data, unauthorized modification of documents, or a complete shutdown of the content management service.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Content Server component of Oracle WebCenter Content version 14.1.2.0.0. The flaw is easily exploitable by an unauthenticated remote attacker via the HTTP protocol, though it requires a victim (other than the attacker) to perform a specific action, such as clicking a link or visiting a malicious site while authenticated. Due to a scope change (S:C), a successful attack can propagate beyond the WebCenter Content environment to impact other products. Exploitation can result in a complete takeover of the affected Oracle WebCenter Content instance, granting the attacker full confidentiality, integrity, and availability impacts.

Affected products

  • Oracle WebCenter Content 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Security Alert published

References

Related threats