Executive brief
Oracle WebCenter Content is a platform used by organizations to manage and share business documents and digital assets. A critical vulnerability has been identified that allows an unauthorized person to take complete control of the system if a legitimate user performs a specific action, such as clicking a malicious link. This could lead to the theft of sensitive corporate data, a total service outage, or the compromise of other connected business systems.
Technical details
This vulnerability exists in the Content Server component of Oracle WebCenter Content version 14.1.2.0.0. It is classified as easily exploitable via the HTTP network vector without requiring prior authentication. While the specific vulnerability class is not explicitly named, the CVSS vector (UI:R and S:C) strongly suggests a high-impact Cross-Site Scripting (XSS) or Cross-Site Request Forgery (CSRF) variant that allows for session hijacking or administrative takeover. A successful exploit requires a legitimate user to interact with a malicious element, potentially leading to a full compromise of the WebCenter Content environment and impacting associated products due to the scope change. Users should refer to the Oracle June 2026 Security Alert for patching information.
Affected products
- Oracle WebCenter Content 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: NVD published the advisory based on Oracle's security alert.