Executive brief
Oracle WebCenter Content is a document management platform used by businesses to store and organize corporate records. A security vulnerability in the Content Server component allows an unauthorized person to access and read certain sensitive data over the internet. This could lead to the exposure of internal documents or configuration details without requiring any login credentials.
Technical details
This vulnerability is classified as an information exposure (CWE-200) within the Content Server component of Oracle WebCenter Content. It is easily exploitable by an unauthenticated attacker with network access via HTTP. The flaw does not require user interaction and has a low attack complexity. Successful exploitation results in unauthorized read access to a subset of data managed by the WebCenter Content system. The vulnerability specifically affects version 14.1.2.0.0.
Affected products
- Oracle WebCenter Content 14.1.2.0.0
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle via NVD.
- 2026-06-17: advisory: Oracle Critical Patch Update advisory published.