Junglewise Threat Intelligence

CVE-2026-46805: Oracle WebCenter Content improper access control in Content Server

CVE-2026-46805 · Severity: critical · CVSS 9.3 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, contains a critical security vulnerability. An attacker can exploit this flaw to gain full access to sensitive business data, allowing them to view, change, or delete information. While the attack is launched over the network, it requires a legitimate user to perform an action, such as clicking a malicious link, to succeed.

Technical details

An improper access control vulnerability (CWE-284) exists in the Content Server component of Oracle WebCenter Content version 14.1.2.0.0. The flaw is easily exploitable by an unauthenticated remote attacker via HTTP. Successful exploitation requires human interaction (UI:R) from a person other than the attacker. Due to a scope change (S:C), the impact can extend beyond the WebCenter Content environment to other products. An attacker can achieve complete confidentiality and integrity impacts, resulting in unauthorized access to or modification of all accessible data. Availability is not impacted according to the CVSS vector.

Affected products

  • Oracle WebCenter Content 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References

Related threats