Executive brief
Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a security vulnerability in its Content Server component. An attacker can exploit this flaw over the network to gain full control of the system, though the attack requires a legitimate user to perform a specific action, such as clicking a malicious link. If successful, this could lead to the total compromise of sensitive corporate data and a disruption of document management services.
Technical details
A vulnerability in the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0) allows for a complete system takeover. The flaw is categorized by a CVSS 3.1 score of 8.8, indicating high impacts on confidentiality, integrity, and availability. While the attack vector is network-based (HTTP) and requires no prior authentication, it is dependent on user interaction (UI:R), suggesting a client-side attack such as Cross-Site Scripting (XSS) or Cross-Site Request Forgery (CSRF) that leads to administrative session compromise. Oracle has addressed this in the July 2026 Critical Patch Update.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released