Junglewise Threat Intelligence

CVE-2026-46787: Oracle WebCenter Content CSRF in Content Server

CVE-2026-46787 · Severity: high · CVSS 8 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle WebCenter Content, a platform used by organizations to manage and share business documents. An attacker could trick a legitimate user into performing unintended actions, potentially leading to the unauthorized modification or theft of sensitive corporate data. This could result in a significant breach of confidentiality and data integrity across the organization's content management system.

Technical details

This vulnerability is classified as Cross-Site Request Forgery (CSRF) within the Content Server component of Oracle WebCenter Content (version 14.1.2.0.0). It is triggered via the HTTP protocol and requires an unauthenticated remote attacker to induce a legitimate user to perform a specific action (user interaction). The vulnerability is noted for having a 'scope change' (S:C), meaning a successful exploit can impact components beyond the immediate WebCenter Content environment. Attackers can achieve full unauthorized access to or modification of all data accessible to the compromised user session. Oracle has addressed this in the June 2026 security alert.

Affected products

  • Oracle WebCenter Content 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References

Related threats