Executive brief
Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, contains a security vulnerability in its Content Server component. A low-privileged user can exploit this flaw to gain unauthorized access to sensitive business data or modify and delete critical files. Successful exploitation requires a legitimate user to perform a specific action, but it can lead to a significant breach of confidentiality and data integrity across the system.
Technical details
An improper access control vulnerability (CWE-284) exists in the Content Server component of Oracle WebCenter Content version 14.1.2.0.0. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP, though it requires human interaction from a victim (UI:R). The vulnerability involves a scope change (S:C), meaning an exploit can impact components beyond the immediate WebCenter Content environment. Successful exploitation allows for the unauthorized creation, deletion, or modification of critical data, as well as complete unauthorized access to all data accessible by the application. Oracle has addressed this in the June 2026 security alerts.
Affected products
- Oracle WebCenter Content 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published