Executive brief
Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, contains a security vulnerability in its Content Server component. A high-privileged attacker could exploit this flaw to take full control of the system, potentially leading to the theft of sensitive data or disruption of business operations. Successful exploitation requires a legitimate user to perform a specific action, such as clicking a malicious link, and the impact may extend to other integrated business systems.
Technical details
A vulnerability in the Content Server component of Oracle WebCenter Content (version 14.1.2.0.0) is classified as Improper Access Control (CWE-284). The flaw is reachable via HTTP and requires high privileges to exploit. A successful attack involves a scope change (S:C), meaning the impact can extend beyond the WebCenter Content environment to other products. While the specific technical root cause is described as 'easily exploitable,' it requires human interaction (UI:R) from a user other than the attacker. Successful exploitation can result in a complete takeover of the affected Oracle WebCenter Content instance.
Affected products
- Oracle WebCenter Content 14.1.2.0.0
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD record published