Executive brief
A vulnerability in Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, could allow an attacker with access to the underlying server to gain unauthorized access to sensitive data. This flaw is particularly serious because it may allow an attacker to reach data in other connected systems beyond the document repository itself. Successful exploitation could lead to a significant breach of confidential business information.
Technical details
This vulnerability exists in the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0). It is classified as a local attack (AV:L) requiring the attacker to have logon access to the infrastructure where the software executes, though no specific application privileges are required (PR:N). The vulnerability is characterized by a 'Scope Change' (S:C), indicating that a successful exploit can impact components or products outside the immediate security scope of the Content Server. The primary impact is a high loss of confidentiality (C:H), potentially granting complete access to all data accessible by the service. Users are advised to apply the relevant patches from the Oracle Critical Patch Update (CPU).
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published