Junglewise Threat Intelligence

CVE-2026-46806: Oracle WebCenter Content Open Redirect in Content Server

CVE-2026-46806 · Severity: high · CVSS 8.2 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

A vulnerability in Oracle WebCenter Content's Content Server component could allow an unauthorized person to gain access to sensitive business documents. By tricking a legitimate user into clicking a malicious link, an attacker can view, modify, or delete critical data within the system. This could lead to significant data breaches or the unauthorized alteration of corporate records.

Technical details

This vulnerability is classified as an Open Redirect (CWE-601) within the Content Server component of Oracle WebCenter Content version 14.1.2.0.0. It is remotely exploitable via HTTPS without authentication, though it requires human interaction (UI:R) from a victim. The vulnerability carries a 'Scope Change' (S:C) designation, meaning an attack on WebCenter Content can impact other integrated products. Successful exploitation allows an attacker to gain unauthorized read access to all accessible data (Confidentiality: High) and perform unauthorized updates or deletions of certain data (Integrity: Low). Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation details.

Affected products

  • Oracle WebCenter Content 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Security Alert published

References

Related threats