Executive brief
A vulnerability in Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, could allow an attacker to compromise sensitive business data. An attacker with low-level access could potentially view, modify, or delete critical files, though the attack is difficult to perform and requires a legitimate user to take a specific action. This could lead to significant data breaches or unauthorized changes to important company records.
Technical details
This vulnerability affects the Content Server component of Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0. It is classified as difficult to exploit (AC:H) and requires a low-privileged attacker with network access via HTTP. The exploit requires human interaction from a victim (UI:R) and involves a scope change (S:C), meaning the impact can extend beyond the WebCenter Content application itself. Successful exploitation can lead to unauthorized creation, deletion, or modification of all accessible data, as well as complete unauthorized access to critical information. The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed: Initial disclosure in Oracle Critical Patch Update
- 2026-07-21: advisory: NVD publication date