Junglewise Threat Intelligence

CVE-2026-46791: Oracle WebCenter Content improper access control in Content Server

CVE-2026-46791 · Severity: high · CVSS 7.5 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content is a platform used by organizations to manage and share business documents and digital assets. A security vulnerability in its Content Server component allows an unauthorized person to access the system over the internet without needing a username or password. If exploited, an attacker could view or steal sensitive corporate data, potentially compromising all information stored within the system.

Technical details

A vulnerability classified as improper access control (CWE-284) exists in the Content Server component of Oracle WebCenter Content version 14.1.2.0.0. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. By sending specially crafted requests, an attacker can bypass security restrictions to gain unauthorized access to critical data or complete access to all data accessible by the WebCenter Content application. The vulnerability specifically impacts confidentiality but does not appear to affect system integrity or availability according to the CVSS vector. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle WebCenter Content 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: NVD published the CVE record based on Oracle's security alert.

References

Related threats