Junglewise Threat Intelligence

CVE-2026-46790: Oracle WebCenter Content information disclosure in Content Server

CVE-2026-46790 · Severity: medium · CVSS 5.3 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content is a document management platform used by businesses to store and organize corporate records. A security vulnerability in the Content Server component allows an unauthorized person to access and read certain sensitive data over the internet. This could lead to the exposure of internal documents or configuration details without requiring any login credentials.

Technical details

This vulnerability is classified as an information exposure (CWE-200) within the Content Server component of Oracle WebCenter Content. It is easily exploitable by an unauthenticated attacker with network access via HTTP. The flaw does not require user interaction and has a low attack complexity. Successful exploitation results in unauthorized read access to a subset of data managed by the WebCenter Content system. The vulnerability specifically affects version 14.1.2.0.0.

Affected products

  • Oracle WebCenter Content 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle via NVD.
  • 2026-06-17: advisory: Oracle Critical Patch Update advisory published.

References

Related threats