Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in Oracle WebCenter Content’s Content Server component and allows an attacker to execute arbitrary code on the affected system without authentication. By sending a specially crafted HTTP request, a remote attacker can compromise the integrity, confidentiality, and availability of the application, potentially leading to full takeover of the WebCenter Content instance. The weakness is a classic example of improper access control that can lead to remote code execution.

Affected Systems

Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These are part of Oracle Fusion Middleware and are used in enterprise content management deployments. The vulnerability impacts only systems that expose the WebCenter Content HTTP interface to the network, as the exploit requires network access to the application port.

Risk and Exploitability

The CVSS 3.1 base score of 9.8 indicates critical severity, with high effects on confidentiality, integrity, and availability. The EPSS score is below 1%, suggesting that while the likelihood of exploitation at any given time is low, the impact of a successful attack is catastrophic. The vulnerability is listed as not in the CISA KEV catalog, but the exploit path is straightforward – an unauthenticated attacker can trigger the flaw via an HTTP request, so monitoring and patching are essential. Given the ease of exploitation, the risk remains high until the vulnerability is remediated.

Generated by OpenCVE AI on August 4, 2026 at 03:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle product patch for Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 as documented in Oracle’s CPU Jul 2026 security alert.
  • Restrict external HTTP access to the WebCenter Content server or place it behind a firewall that only allows traffic from trusted networks.
  • Disable anonymous web access and enforce authentication to prevent unauthenticated interactions with the application.

Generated by OpenCVE AI on August 4, 2026 at 03:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle WebCenter Content

Tue, 28 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle WebCenter Content via HTTP
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle WebCenter Content via HTTP
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:00.828Z

Reserved: 2026-07-08T15:51:40.536Z

Link: CVE-2026-60435

cve-icon Vulnrichment

Updated: 2026-07-24T14:08:46.094Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:00:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function