Executive brief
Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, contains a critical security flaw. An unauthorized person can remotely take full control of the system over the internet without needing a password. This could lead to the theft of sensitive business data, total service disruption, and may allow the attacker to compromise other connected corporate systems.
Technical details
A vulnerability in the Web Content Management component of Oracle WebCenter Content (part of Oracle Fusion Middleware) allows for a complete system takeover. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Notably, the vulnerability includes a 'scope change' (Status: C in CVSS), meaning a successful exploit can impact resources beyond the security scope of the WebCenter Content application itself. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Published by Oracle in the July 2026 CPU