Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle WebCenter Content permits an unauthenticated attacker who can reach the application over HTTP to compromise the system without a valid account; although difficult and requiring interaction from a user other than the attacker, a successful exploit would grant the attacker full control over the Content Server, exposing confidential data, enabling unauthorized changes, and disrupting availability. This flaw involves weaknesses in input validation, improper authentication, and misconfiguration that facilitate remote code execution.

Affected Systems

Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 from Oracle Corporation are affected. These deployments are part of Oracle Fusion Middleware and are commonly used in enterprise content management environments.

Risk and Exploitability

The CVSS base score of 8.3 indicates high severity, while the EPSS score of less than 1% shows a very low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. Attacks require network access to the HTTP interface and a susceptible user to interact, likely via social engineering. Once compromised, the attacker can fully control the Content Server and potentially impact integrated products due to a scope change.

Generated by OpenCVE AI on August 4, 2026 at 16:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 update, which patches this vulnerability.
  • Restrict inbound HTTP traffic to the Content Server by allowing only trusted IPs or networks to connect.
  • Monitor application logs for failed authentication attempts, unexpected configuration changes, and anomalous activity, and investigate anomalies promptly.

Generated by OpenCVE AI on August 4, 2026 at 16:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Compromise of Oracle WebCenter Content via HTTP

Sun, 02 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Compromise of Oracle WebCenter Content via HTTP
Weaknesses CWE-285

Tue, 28 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Oracle WebCenter Content unauthenticated remote access vulnerability

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-352
CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Oracle WebCenter Content unauthenticated remote access vulnerability
Weaknesses CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:30.999Z

Reserved: 2026-07-08T15:51:40.549Z

Link: CVE-2026-60640

cve-icon Vulnrichment

Updated: 2026-07-27T12:55:17.227Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:04.750

Modified: 2026-07-29T19:19:27.720

Link: CVE-2026-60640

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:00:13Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')