Executive brief
Oracle WebCenter Content is an enterprise document and content management system used to store and manage business documents and data. This vulnerability allows an unauthenticated attacker to trick users into performing unauthorized actions—such as modifying, deleting, or accessing sensitive documents—through a malicious web request. Successful exploitation could lead to data breach, unauthorized data modification, or service disruption affecting the organization's content management operations.
Technical details
This is a cross-site request forgery (CSRF) vulnerability in Oracle WebCenter Content's Content Server component that requires user interaction to exploit. The vulnerability is easily exploitable over the network via HTTP by an unauthenticated attacker who crafts a malicious request that, when accessed by an authorized user, performs unintended actions. Successful attacks can result in unauthorized read, update, insert, or delete access to WebCenter Content data, as well as partial denial of service. The scope is marked as changed, indicating that the vulnerability in WebCenter Content may significantly impact other Oracle Fusion Middleware products. No patch information is currently available based on the advisory.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-08-18: disclosed