Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 suffer from a combination of improper input validation, cross‑site request forgery, open redirect, and reflected cross‑site scripting weaknesses. This flaw allows an unauthenticated attacker with network access via HTTP to bypass authentication controls and ultimately gain full control of the Content Server, resulting in loss of confidentiality, integrity, and availability.

Affected Systems

Affected systems are Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0, the primary applications within Oracle Fusion Middleware that provide content management services.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 indicates high severity. The EPSS score of <1% suggests a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw is reachable over HTTP and requires user interaction (UI:R), a determined attacker could coerce or trick a user into initiating the exploit, making the risk relevant for environments exposing WebCenter Content to untrusted networks.

Generated by OpenCVE AI on August 4, 2026 at 16:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle CPU update for WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 as published by Oracle
  • Restrict direct HTTP access to trusted network segments or enforce IP whitelisting
  • Configure a web application firewall or input validation controls to prevent open redirects, reflected XSS, and CSRF attacks, and enable logging of anomalous HTTP traffic

Generated by OpenCVE AI on August 4, 2026 at 16:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Takeover Vulnerability in Oracle WebCenter Content

Sun, 02 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated remote takeover via WebCenter Content HTTP interface
Weaknesses CWE-284
CWE-862

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-352
CWE-601
CWE-79
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated remote takeover via WebCenter Content HTTP interface
Weaknesses CWE-284
CWE-862

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:27.969Z

Reserved: 2026-07-08T15:51:40.549Z

Link: CVE-2026-60636

cve-icon Vulnrichment

Updated: 2026-07-27T12:52:21.553Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:00:13Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')