Executive brief
Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a security vulnerability in its Content Server component. An attacker can exploit this flaw by tricking a legitimate user into performing a specific action, potentially leading to the theft of sensitive corporate data or unauthorized modification of files. This could result in a significant breach of confidential information and a partial disruption of the document management service.
Technical details
A vulnerability in the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0) allows an unauthenticated remote attacker to compromise the system via HTTP. The exploit requires human interaction from a person other than the attacker, suggesting a UI-based attack vector such as Cross-Site Scripting (XSS) or Cross-Site Request Forgery (CSRF). Successful exploitation can lead to unauthorized access to critical data, unauthorized data modification (update, insert, or delete), and a partial denial of service. The vulnerability is rated with a CVSS 3.1 base score of 7.6, reflecting high confidentiality impact and low integrity/availability impacts.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory