Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the Oracle WebCenter Content product allows an unauthenticated attacker with network access via HTTP to compromise the Content Server. Based on the description, it is inferred that the flaw results in an authentication bypass, although the precise mechanism is not detailed. The impact includes complete compromise of confidentiality, integrity, and availability, as the attacker can potentially execute arbitrary commands or read/write any data. The weakness corresponds to CWE‑306, reflecting missing or inadequate authentication.

Affected Systems

Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle Fusion Middleware are affected. These products are deployed in many enterprise environments, providing content and collaboration services.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 indicates a high ratio of confidentiality, integrity, and availability impact. The EPSS score of less than 1 % suggests that exploitation is currently rare, and the vulnerability is not listed in CISA’s KEV catalog. The probable attack vector is a network‑based HTTP request that does not require prior authentication and can be executed by any external party with internet exposure.

Generated by OpenCVE AI on August 2, 2026 at 22:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle WebCenter Content patch released in the July 2026 CPU or upgrade to a newer, non‑affected version
  • Restrict or block HTTP access to the Content Server endpoints until the patch or upgrade is applied
  • Enforce authentication and authorization checks on all Content Server APIs, ensuring that only authenticated users can perform privileged actions

Generated by OpenCVE AI on August 2, 2026 at 22:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Authentication Bypass Enables Full Takeover of Oracle WebCenter Content

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution Vulnerability in Oracle WebCenter Content Leading to Takeover
Weaknesses CWE-284

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution Vulnerability in Oracle WebCenter Content Leading to Takeover
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:11.408Z

Reserved: 2026-07-08T15:51:40.538Z

Link: CVE-2026-60462

cve-icon Vulnrichment

Updated: 2026-07-24T18:09:01.535Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function