Junglewise Threat Intelligence

CVE-2026-46795: Oracle WebCenter Content access control bypass in Content Server

CVE-2026-46795 · Severity: critical · CVSS 9.3 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle WebCenter Content, a platform used by organizations to manage and share business documents. An attacker can exploit this flaw to gain full access to sensitive corporate data, allowing them to view, change, or delete critical information. While the attack requires a legitimate user to perform a specific action, such as clicking a link, the potential impact is severe and could lead to a total compromise of the document management system.

Technical details

A vulnerability classified as Improper Access Control (CWE-284) exists in the Content Server component of Oracle WebCenter Content version 14.1.2.0.0. The flaw is easily exploitable by an unauthenticated attacker via HTTP over the network. While the attack requires human interaction (User Interaction: Required), it results in a Scope Change (S:C), meaning the compromise can extend beyond the WebCenter Content component to impact other integrated products. Successful exploitation grants the attacker high confidentiality and integrity impacts, effectively allowing unauthorized creation, deletion, or modification of all accessible data within the system.

Affected products

  • Oracle WebCenter Content 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD publication date

References

Related threats