Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle WebCenter Content’s Content Server component allows an unauthenticated attacker with network access over HTTP to trigger actions that create, modify, or delete content. The primary impact is the compromise of confidentiality and integrity for all data stored in the system, as the attacker can gain unauthorized access to critical data or full control over accessible content. Based on the description, it is inferred that the attacker must obtain a third‑party user’s input or action to exploit this flaw, implying a social‑engineering requirement.

Affected Systems

Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are vulnerable. Any installation of these releases without the vendor patch is at risk, and due to the scope change mentioned, additional Oracle Fusion Middleware products that rely on the WebCenter Content server may also be affected.

Risk and Exploitability

The CVSS v3.1 base score of 9.3 indicates critical severity, while the EPSS score of less than 1% suggests a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The required human interaction is inferred from the wording that an attacker needs a third party, so the likely attack vector involves an unauthenticated HTTP endpoint combined with social‑engineering or phishing to prompt the user to initiate the exploit.

Generated by OpenCVE AI on August 4, 2026 at 16:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official vendor patch for Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 as soon as it is released.
  • Restrict HTTP access to the WebCenter Content server with firewalls or access control lists, limiting exposure to trusted networks and preventing unauthenticated requests.
  • Ensure that all URL redirects or external linkage configurations are properly validated to eliminate the risk of CWE‑601 by rejecting unsanitized redirects.

Generated by OpenCVE AI on August 4, 2026 at 16:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Modification Vulnerability in Oracle WebCenter Content
Weaknesses CWE-200
CWE-285

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Modification Vulnerability in Oracle WebCenter Content
Weaknesses CWE-200
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:14.491Z

Reserved: 2026-07-08T15:51:40.549Z

Link: CVE-2026-60632

cve-icon Vulnrichment

Updated: 2026-07-27T12:35:26.082Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:00:13Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')