Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).
Published: 2026-06-16
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker who can reach the WebCenter Content server over HTTP to cause unauthorized creation, deletion or modification of critical content without proper authentication. Because the vulnerability is exploitable from the network and does not require special privileges on the server, the attacker can affect any data accessible through the application. The CVE description notes that human interaction from a person other than the attacker is needed, suggesting that the attack may rely on social engineering or a user following a malicious link. The flaw resides in improper access control and authentication handling in the Content Server component, enabling the attacker to exert full control over the application’s data once the request is accepted.

Affected Systems

The affected product is Oracle WebCenter Content by Oracle Corporation, version 14.1.2.0.0. No other vendors or product versions are listed.

Risk and Exploitability

The CVSS 3.1 base score of 9.3 indicates high confidentiality and integrity impact. The EPSS score is below 1 %, suggesting a very low current exploitation probability, and the vulnerability is not present in the CISA KEV catalog. Because the flaw can be triggered over a normal HTTP connection, the likely attack vector is remote network access to the WebCenter Content server, possibly combined with social‑engineering techniques to obtain the necessary human interaction.

Generated by OpenCVE AI on June 17, 2026 at 21:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle security updates for WebCenter Content to address the authentication bypass vulnerability.
  • Restrict HTTP(S) access to the WebCenter Content server to trusted IP ranges or enforce VPN usage.
  • Strengthen access controls by disabling unused or default accounts and implementing least‑privilege principles.

Generated by OpenCVE AI on June 17, 2026 at 21:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T14:40:04.762Z

Reserved: 2026-05-18T15:55:10.298Z

Link: CVE-2026-46785

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T22:30:05Z

Weaknesses

No weakness.