Junglewise Threat Intelligence

CVE-2026-83353: Oracle WebCenter Content privilege escalation in Content Server

CVE-2026-83353 · Severity: high · CVSS 7.8 · Published 2026-09-15

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content is an enterprise content management system used to store and manage business documents. A low-privilege attacker with local system access can exploit this vulnerability to gain complete control over the Content Server, potentially compromising all stored documents and system availability.

Technical details

This is a privilege escalation vulnerability in Oracle WebCenter Content's Content Server component. The vulnerability requires local access to the infrastructure and low-level privileges, but allows an authenticated attacker to achieve full system compromise affecting confidentiality, integrity, and availability. The affected versions are 12.2.1.4.0 and 14.1.2.0.0. Patches are expected from Oracle; users should monitor Oracle's Critical Patch Updates for available fixes.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats