Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability enables an unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. The vulnerability arises from multiple weaknesses including insufficient input validation (CWE‑20), cross‑site request forgery (CWE‑352), open redirect (CWE‑601), and cross‑site scripting (CWE‑79). Successful exploitation requires user interaction from a third party and can lead to full takeover of the content server, affecting confidentiality, integrity, and availability.

Affected Systems

Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0. These versions of the Content Server component are affected, and any installations using these product releases expose the system to risk.

Risk and Exploitability

The CVSS base score of 8.8 reflects high severity. The EPSS score is less than 1%, indicating low probability of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based over HTTP with no prior authentication and requires user interaction, meaning an attacker must persuade a legitimate user to complete an action that triggers the exploit.

Generated by OpenCVE AI on August 4, 2026 at 03:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch released by Oracle for WebCenter Content 12.2.1.4.0 and 14.1.2.0.0.
  • Restrict inbound HTTP traffic to WebCenter Content servers to trusted networks or VPN access.
  • Educate users about phishing and social engineering tactics and monitor for suspicious activity.

Generated by OpenCVE AI on August 4, 2026 at 03:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated WebCenter Content Remote Takeover via HTTP Exploit

Tue, 28 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Oracle WebCenter Content Remote Takeover via Unauthenticated HTTP Exploit
Weaknesses CWE-284

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-352
CWE-601
CWE-79
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Oracle WebCenter Content Remote Takeover via Unauthenticated HTTP Exploit
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:29.500Z

Reserved: 2026-07-08T15:51:40.549Z

Link: CVE-2026-60638

cve-icon Vulnrichment

Updated: 2026-07-27T12:40:33.203Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:30:03Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')