Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-07-21
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker with low privilege but network access via HTTP to compromise the Oracle WebCenter Content Content Server. Successful exploitation permits reading, inserting, updating, or deleting data, granting full control over accessible content. The flaw is an access control weakness (CWE‑284) that leads to confidentiality compromise and integrity degradation.

Affected Systems

Oracle WebCenter Content version 12.2.1.4.0 and 14.1.2.0.0 are affected. The advisory notes that the vulnerability could also impact other Oracle Fusion Middleware products due to a scope change.

Risk and Exploitability

The CVSS base score of 8.5 classifies this as high severity. The EPSS value of less than 1% indicates a low probability of exploitation, and the vulnerability is not catalogued in CISA KEV. The attack vector is network-based, requiring only low privilege and no user interaction, so an internal or compromised host could exploit it if the necessary controls are not in place. No public exploits have been reported.

Generated by OpenCVE AI on August 4, 2026 at 17:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle update released in CPU July 2026 for WebCenter Content 12.2.1.4.0 and 14.1.2.0.0
  • Restrict external access to the WebCenter Content services by firewalling or requiring VPN, ensuring only trusted hosts can reach the HTTP interface
  • Enforce strict role‑based access control, remove any default or unused user accounts that have write permissions, and audit existing ACLs for least privilege

Generated by OpenCVE AI on August 4, 2026 at 17:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Access in Oracle WebCenter Content Enabling Unauthorized Data Manipulation

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Access in Oracle WebCenter Content Enabling Unauthorized Data Manipulation

Wed, 29 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Vulnerability in Oracle WebCenter Content Allowing Unauthorized Data Access
Weaknesses CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Vulnerability in Oracle WebCenter Content Allowing Unauthorized Data Access
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T19:26:42.154Z

Reserved: 2026-07-08T15:51:40.537Z

Link: CVE-2026-60444

cve-icon Vulnrichment

Updated: 2026-07-24T14:19:48.582Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:30:03Z

Weaknesses