Executive brief
Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a vulnerability in its Content Server component. An unauthorized person could potentially use this flaw over the network to take full control of the system. If exploited, this could lead to the theft of sensitive corporate data, unauthorized modification of documents, or a total shutdown of the content management service.
Technical details
A vulnerability exists in the Content Server component of Oracle WebCenter Content (part of Oracle Fusion Middleware). The flaw is accessible via the HTTP protocol and does not require user authentication. While the attack complexity is rated as high, a successful exploit allows an unauthenticated attacker with network access to achieve a complete compromise of the application, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published