Executive brief
A critical vulnerability has been identified in Oracle WebCenter Content, a platform used by organizations to manage and share business documents and digital assets. An attacker can exploit this flaw over the internet without needing any login credentials or user interaction. If successful, the attacker could gain full access to view, modify, or delete sensitive corporate data, potentially leading to significant data breaches or loss of critical business information.
Technical details
A vulnerability exists in the Web Content Management component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. The vulnerability allows for unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to all data accessible within the WebCenter Content environment. The CVSS 3.1 score of 9.1 reflects high confidentiality and integrity impacts with no availability impact reported. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published