Executive brief
Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a critical security flaw in its Content Server component. An unauthorized person can use this vulnerability over the internet to gain full control of the system without needing a username or password. This could lead to the theft of sensitive corporate data, disruption of business operations, and total compromise of the document management environment.
Technical details
A critical vulnerability exists in the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is categorized as a missing authentication for a critical function (CWE-306), allowing an unauthenticated attacker with network access via HTTP to bypass security controls. This is an easily exploitable vulnerability that requires no user interaction. A successful exploit results in a complete takeover of the Oracle WebCenter Content instance, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation details.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory