Executive brief
Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, contains a critical vulnerability in its Content Server component. An unauthenticated attacker could exploit this flaw to gain full access to sensitive data or modify critical information, provided they can trick a legitimate user into performing a specific action. This could lead to a total compromise of the document management system and potentially impact other integrated business applications.
Technical details
A vulnerability in the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0) allows unauthenticated attackers to compromise the application via the HTTP protocol. The vulnerability is characterized by a CVSS 3.1 score of 9.3, indicating a high impact on confidentiality and integrity with a scope change (S:C), suggesting the attack can impact components beyond the immediate application. Exploitation requires user interaction (UI:R), likely through a Cross-Site Scripting (XSS) or Cross-Site Request Forgery (CSRF) vector. Successful attacks grant the ability to create, delete, or modify all data within the WebCenter Content environment. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation details.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle