Executive brief
Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a security vulnerability in its Web Content Management component. An attacker with low-level access to the network can trick a legitimate user into performing an action that allows the attacker to take full control of the system. This could lead to the unauthorized access, modification, or deletion of sensitive corporate documents and a total disruption of the content management service.
Technical details
A vulnerability exists in the Web Content Management component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is classified as easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise the application. The attack vector requires human interaction (UI:R) from a victim, suggesting a vulnerability class such as Cross-Site Request Forgery (CSRF) or a similar client-side injection that leads to account takeover. Successful exploitation results in high impacts to confidentiality, integrity, and availability (C:H/I:H/A:H). Users are advised to consult the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Initial publication by Oracle and NVD