Junglewise Threat Intelligence

CVE-2026-46788: Oracle WebCenter Content access control bypass in Content Server

CVE-2026-46788 · Severity: high · CVSS 8.4 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, contains a security vulnerability in its Content Server component. A high-privileged attacker could exploit this flaw to take full control of the system, potentially leading to the theft of sensitive data or disruption of business operations. Successful exploitation requires a legitimate user to perform a specific action, such as clicking a malicious link, and the impact may extend to other integrated business systems.

Technical details

A vulnerability in the Content Server component of Oracle WebCenter Content (version 14.1.2.0.0) is classified as Improper Access Control (CWE-284). The flaw is reachable via HTTP and requires high privileges to exploit. A successful attack involves a scope change (S:C), meaning the impact can extend beyond the WebCenter Content environment to other products. While the specific technical root cause is described as 'easily exploitable,' it requires human interaction (UI:R) from a user other than the attacker. Successful exploitation can result in a complete takeover of the affected Oracle WebCenter Content instance.

Affected products

  • Oracle WebCenter Content 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD record published

References

Related threats