Executive brief
A vulnerability exists in Oracle WebCenter Content, a platform used by organizations to manage and share business documents. A low-privileged user could exploit this flaw to gain unauthorized access to sensitive corporate data or modify and delete critical files. This attack requires a legitimate user to interact with a malicious link or file, and the impact could extend beyond the content management system to other connected business applications.
Technical details
This vulnerability affects the Content Server component of Oracle WebCenter Content version 14.1.2.0.0. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. The exploit requires human interaction (UI:R) from a victim other than the attacker. Notably, the vulnerability involves a scope change (S:C), meaning a successful exploit can impact security components beyond the immediate WebCenter Content environment. Attackers can achieve high confidentiality and integrity impacts, including the ability to create, delete, or modify all accessible data within the system.
Affected products
- Oracle WebCenter Content 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published