Executive brief
Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, contains a vulnerability that could allow an attacker to gain full access to sensitive data. By tricking a legitimate user into performing a specific action, a low-privileged attacker can view, modify, or delete critical business information. This could lead to significant data breaches or the loss of important organizational records.
Technical details
A vulnerability in the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0) allows for a scope-changing attack, likely a Cross-Site Scripting (XSS) or similar injection flaw given the requirement for human interaction and the 'Scope: Changed' CVSS metric. An attacker with low-level privileges can exploit this over HTTP to gain unauthorized access to or modify critical data. The exploit requires a victim other than the attacker to interact with a malicious link or component. Successful exploitation can result in complete confidentiality and integrity impacts across the affected product and potentially integrated systems.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory