Executive brief
Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a high-severity vulnerability in its Content Server component. An attacker could exploit this flaw over the network to gain full control of the system, potentially leading to the theft of sensitive corporate data or a total service outage. While the attack is difficult to execute, a successful breach would compromise the confidentiality, integrity, and availability of the entire content management environment.
Technical details
This vulnerability exists in the Content Server component of Oracle WebCenter Content (part of Oracle Fusion Middleware). It is classified as a high-severity issue that allows an unauthenticated attacker with network access via HTTPS to compromise the target system. The attack complexity is rated as high, suggesting that successful exploitation may require specific environmental conditions or timing. If successfully exploited, the attacker can achieve a complete takeover of the WebCenter Content instance, impacting confidentiality, integrity, and availability. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.