Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
Published: 2026-06-16
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle WebCenter Content 14.1.2.0.0 is vulnerable to an unauthenticated HTTPS exploit that requires an attacker to socially engineer a second user into executing a crafted request. The flaw, identified as a web redirect weakness (CWE-601), lets the attacker gain unauthorized access to critical data, all data normally available within WebCenter Content, and allows insertion, updating, or deletion of records. The CVSS v3.1 baseline score of 8.2 reflects a high confidentiality impact, low integrity impact, and a scope change, indicating that the vulnerability can affect the overall system integrity beyond the direct target.

Affected Systems

The affected product is Oracle WebCenter Content version 14.1.2.0.0, part of Oracle Fusion Middleware. The advisory notes that attacks originating against this product may also impact additional Oracle services hosted in the same environment.

Risk and Exploitability

The vulnerability is rated CVSS 8.2 with an EPSS score of less than 1%, indicating a low but non-zero chance of exploitation. It is not listed in the CISA KEV catalog. Exploitation occurs over HTTPS without authentication, with the primary barrier being the need for a human victim to interact with a malicious payload. Once the flaw is leveraged, the attacker can exercise unrestricted read or modify privileges on all WebCenter Content data. The potential for scope change amplifies the risk to other Oracle products within the same environment.

Generated by OpenCVE AI on August 12, 2026 at 05:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch referenced in the Security Alert that fixes CVE-2026-46806
  • Restrict HTTPS access to WebCenter Content to trusted networks by configuring firewalls or VPNs
  • Segment the network and limit user permissions to reduce the potential impact of compromised accounts

Generated by OpenCVE AI on August 12, 2026 at 05:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Vulnerability Enabling Unauthorized Access to Oracle WebCenter Content

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T15:30:03.873Z

Reserved: 2026-05-18T15:55:10.300Z

Link: CVE-2026-46806

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-06-17T10:53:58.260

Modified: 2026-06-17T20:35:38.417

Link: CVE-2026-46806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T05:45:04Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')