Executive brief
A vulnerability in Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, could allow an unauthorized user to take full control of the system. To succeed, an attacker needs basic access to the network and must trick a legitimate user into performing a specific action. A successful exploit could lead to the theft of sensitive business data, unauthorized modification of content, or a complete disruption of document management services.
Technical details
This vulnerability exists in the Web Content Management component of Oracle WebCenter Content (Oracle Fusion Middleware). It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the application. The attack requires user interaction (UI:R) from a person other than the attacker, suggesting a vulnerability class such as Cross-Site Scripting (XSS) or Cross-Site Request Forgery (CSRF) that leads to full session takeover. Successful exploitation grants the attacker full control over Confidentiality, Integrity, and Availability (C:H/I:H/A:H). Affected versions include 12.2.1.4.0 and 14.1.2.0.0.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published