Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Content Server component of Oracle WebCenter Content and permits an attacker with network access over HTTP to gain unauthorized control of the system. Because no authentication is required and the exploitation pathway is simple, an unauthenticated attacker can seize the entire platform, resulting in loss of confidentiality, integrity and availability. The attack also demands a human interaction from an entity other than the attacker, implying a social‑engineering component to the successful exploitation.

Affected Systems

Affected product: Oracle WebCenter Content, part of Oracle Fusion Middleware. Versions 12.2.1.4.0 and 14.1.2.0.0 are impacted. The flaw lies within the Content Server module.

Risk and Exploitability

The CVSS base score of 8.8 underscores a high‑severity risk, while the EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. Although the vulnerability is not listed in the CISA KEV catalog, the combination of remote accessibility via HTTP and the ability to fully takeover the platform makes it a pressing issue. Attackers may exploit this once the service is exposed over the network, so preventing external HTTP access is critical.

Generated by OpenCVE AI on August 2, 2026 at 21:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch for Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 as detailed in the Oracle CPU July 2026 alert.
  • If a patch is not yet available, block external HTTP traffic to the WebCenter Content servlet or restrict access to trusted IP ranges until the fix is deployed.
  • Disable anonymous or default user access for the Content Server service to limit exposure.
  • Monitor application logs for unusual authentication or session activity, especially from uncontrolled interfaces, and investigate any suspicious events promptly.

Generated by OpenCVE AI on August 2, 2026 at 21:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Takeover in Oracle WebCenter Content

Tue, 28 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Exploit Compromising Oracle WebCenter Content
Weaknesses CWE-284

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-352
CWE-601
CWE-79
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Exploit Compromising Oracle WebCenter Content
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:28.728Z

Reserved: 2026-07-08T15:51:40.549Z

Link: CVE-2026-60637

cve-icon Vulnrichment

Updated: 2026-07-27T12:53:21.946Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:45:03Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')