Executive brief
Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a high-severity vulnerability in its Content Server component. An attacker with basic user credentials can exploit this flaw over the network to gain full control of the system. This could lead to the unauthorized access, modification, or deletion of sensitive corporate documents and a total disruption of the content management service.
Technical details
A vulnerability exists in the Content Server component of Oracle WebCenter Content (part of Oracle Fusion Middleware). The flaw is classified as easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise the application. Successful exploitation can lead to a complete takeover of the WebCenter Content instance, impacting confidentiality, integrity, and availability. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. Users are advised to consult the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory