Executive brief
Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a security vulnerability in its Web Content Management component. An attacker with basic user access can exploit this flaw to gain full control over the system, provided they can trick another user into performing a specific action. A successful attack could lead to the theft of sensitive corporate data, unauthorized modification of documents, or a complete disruption of the content management service.
Technical details
This vulnerability exists in the Web Content Management component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0). It is classified as easily exploitable, requiring only low-privileged (PR:L) credentials and network access via HTTP. The attack vector requires human interaction (UI:R) from a victim, suggesting a vulnerability class such as Cross-Site Scripting (XSS) or Cross-Site Request Forgery (CSRF) that leads to account takeover. Successful exploitation results in high impacts to confidentiality, integrity, and availability. Oracle addressed this in the July 2026 Critical Patch Update.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD