Executive brief
A vulnerability in Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, could allow an attacker to take complete control of the system. To succeed, an attacker must trick a legitimate user into performing a specific action, such as clicking a malicious link. If exploited, this could lead to the theft of sensitive business data, unauthorized modification of records, or a total disruption of document management services.
Technical details
A vulnerability in the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0) allows an unauthenticated remote attacker to compromise the application over HTTP. The vulnerability is characterized by a CVSS 3.1 score of 8.8, indicating high impacts on confidentiality, integrity, and availability. While the attack vector is network-based and requires low complexity, it necessitates human interaction (UI:R) from a legitimate user to be successful. Successful exploitation can lead to a complete takeover of the WebCenter Content instance. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published