Executive brief
Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, contains a high-severity vulnerability in its Content Server component. An unauthenticated attacker can exploit this flaw over the network to potentially take full control of the system, provided they can trick a legitimate user into performing a specific action. Successful exploitation could lead to the theft of sensitive business data, unauthorized modification of records, or a total service outage.
Technical details
This vulnerability exists in the Content Server component of Oracle WebCenter Content (formerly Universal Content Management). It is classified as easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the target environment. The attack requires human interaction from a person other than the attacker (UI:R), suggesting a vulnerability class such as Cross-Site Request Forgery (CSRF) or a similar client-side attack that leads to administrative takeover. Successful exploitation grants the attacker full control over the Confidentiality, Integrity, and Availability of the affected system. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory