Executive brief
Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, contains a security vulnerability in its Web Content Management component. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could lead to a significant data breach or a partial disruption of the document management service.
Technical details
A vulnerability in the Web Content Management component of Oracle WebCenter Content (part of Oracle Fusion Middleware) allows for unauthorized data access and partial service disruption. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables the attacker to read all accessible data within the system or specific critical files, and can also be used to trigger a partial denial of service (DoS) state. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to apply the relevant patches from the Oracle Critical Patch Update (CPU).
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published