Executive brief
Oracle WebCenter Content is an enterprise content management system used to store and manage business documents. A low-privilege attacker with local system access can exploit this vulnerability to gain complete control over the Content Server, potentially compromising all stored documents and system availability.
Technical details
This is a privilege escalation vulnerability in Oracle WebCenter Content's Content Server component. The vulnerability requires local access to the infrastructure and low-level privileges, but allows an authenticated attacker to achieve full system compromise affecting confidentiality, integrity, and availability. The affected versions are 12.2.1.4.0 and 14.1.2.0.0. Patches are expected from Oracle; users should monitor Oracle's Critical Patch Updates for available fixes.
Affected products
- Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed