Junglewise Threat Intelligence

CVE-2026-70858: Oracle WebCenter Content cross-site request forgery in Content Server

CVE-2026-70858 · Severity: high · CVSS 7.1 · Published 2026-08-18

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content is an enterprise document and content management system used to store and manage business documents and data. This vulnerability allows an unauthenticated attacker to trick users into performing unauthorized actions—such as modifying, deleting, or accessing sensitive documents—through a malicious web request. Successful exploitation could lead to data breach, unauthorized data modification, or service disruption affecting the organization's content management operations.

Technical details

This is a cross-site request forgery (CSRF) vulnerability in Oracle WebCenter Content's Content Server component that requires user interaction to exploit. The vulnerability is easily exploitable over the network via HTTP by an unauthenticated attacker who crafts a malicious request that, when accessed by an authorized user, performs unintended actions. Successful attacks can result in unauthorized read, update, insert, or delete access to WebCenter Content data, as well as partial denial of service. The scope is marked as changed, indicating that the vulnerability in WebCenter Content may significantly impact other Oracle Fusion Middleware products. No patch information is currently available based on the advisory.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-08-18: disclosed

References

Related threats