Executive brief
Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a security vulnerability in its Web Content Management component. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete sensitive corporate data. This could lead to a significant breach of confidential information or the unauthorized alteration of critical business records.
Technical details
A vulnerability exists in the Web Content Management component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. While the specific CWE is not provided, the impact allows for unauthorized creation, deletion, or modification of all data accessible to the product, as well as full unauthorized read access. The attack does not require user interaction. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory