Executive brief
Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a high-severity security flaw. An attacker can exploit this vulnerability over the network to gain full control of the system, though the attack requires a legitimate user to perform a specific action, such as clicking a malicious link. A successful compromise could lead to the theft of sensitive corporate data, unauthorized modification of documents, or a total service outage.
Technical details
A vulnerability in the Content Server component of Oracle WebCenter Content (part of Oracle Fusion Middleware) allows for a full system compromise. The flaw is exploitable by an unauthenticated attacker via the HTTP protocol. While the attack vector is network-based and has low complexity, it requires human interaction (UI:R) from a user other than the attacker, suggesting a class of vulnerability such as Cross-Site Request Forgery (CSRF) or a similar client-side injection that leads to administrative action. Successful exploitation grants the attacker full control over Confidentiality, Integrity, and Availability (C/I/A). Affected versions include 12.2.1.4.0 and 14.1.2.0.0.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Published as part of the Oracle Critical Patch Update (CPU)