Executive brief
Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a critical security flaw in its Content Server component. An attacker can exploit this vulnerability to gain full access to sensitive corporate data, allowing them to view, modify, or delete files without authorization. This attack requires a legitimate user to perform a specific action, such as clicking a malicious link, and could potentially allow the attacker to compromise other connected business systems.
Technical details
A vulnerability in the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0) allows for unauthorized data access and modification. The flaw is categorized by a CVSS 3.1 score of 9.3, indicating a high impact on confidentiality and integrity with a 'Scope Change' (S:C), meaning the exploit can affect components beyond the immediate security scope of the WebCenter Content Server. The attack vector is network-based (HTTP) and requires no prior authentication (PR:N), though it does necessitate user interaction (UI:R) from a victim. Successful exploitation can result in the complete compromise of all accessible data within the application. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation details.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD entry published