Executive brief
Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a vulnerability in its Web Content Management component. A high-privileged attacker can exploit this flaw over the network to gain full control of the system. This could lead to the unauthorized access, modification, or deletion of sensitive corporate documents and a total disruption of the content management service.
Technical details
This vulnerability exists within the Web Content Management component of Oracle WebCenter Content (part of Oracle Fusion Middleware). It is classified as easily exploitable, requiring network access via HTTP. While the attack vector is remote, it requires high-privileged credentials (PR:H) to execute. A successful exploit allows for a complete takeover of the affected Oracle WebCenter Content instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released