Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An insecure privilege handling mechanism in the Content Server component of Oracle WebCenter Content allows a high‑privileged attacker who can reach the server via HTTP to take complete control of the application, thereby compromising confidentiality, integrity, and availability of all data stored and served by the system.

Affected Systems

Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected by this vulnerability.

Risk and Exploitability

The CVSS score of 7.2 classifies the issue as high severity, while the EPSS score of less than 1% indicates a low, yet non‑zero, likelihood of exploitation at the time of this analysis. The vulnerability is not listed in CISA’s KEV catalog. Attackers need network access to the Content Server’s HTTP interface and must possess or obtain high‑privilege credentials within the application. In practice, the vulnerability is considered easily exploitable once the conditions are met, enabling a takeover of the entire WebCenter Content deployment.

Generated by OpenCVE AI on August 4, 2026 at 04:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch that addresses the privilege handling issue for WebCenter Content 12.2.1.4.0 and 14.1.2.0.0.
  • Restrict HTTP access to the Content Server by configuring firewalls or network segmentation so that only trusted hosts can reach the application.
  • Ensure that only the minimum necessary privileges are granted to user accounts that access the Content Server, removing or disabling any unnecessary high‑privilege roles.
  • Monitor authentication and access logs for anomalous activity and enforce auditing policies to detect unauthorized use of privileged accounts.

Generated by OpenCVE AI on August 4, 2026 at 04:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation and Full Takeover via HTTP in Oracle WebCenter Content

Thu, 30 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation and Full Takeover via HTTP in Oracle WebCenter Content

Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Oracle WebCenter Content privilege escalation via HTTP
Weaknesses CWE-284
CWE-285

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Oracle WebCenter Content privilege escalation via HTTP
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:55:59.753Z

Reserved: 2026-07-08T15:51:40.531Z

Link: CVE-2026-60335

cve-icon Vulnrichment

Updated: 2026-07-24T17:24:03.543Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function