Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L).
Published: 2026-07-21
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle WebCenter Content is vulnerable to a remote authentication bypass that can be exploited over HTTP. The flaw allows an unauthenticated attacker to access, modify, or delete protected content and to trigger a partial denial of service. The weakness is rooted in improper access control (CWE‑284) and insecure redirect handling (CWE‑601), with a CVSS 3.1 base score of 7.6 indicating significant confidentiality, integrity, and availability impacts.

Affected Systems

Records show that Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These releases are part of Oracle Fusion Middleware and are commonly deployed by enterprises for managing knowledge and documents.

Risk and Exploitability

The opportunistic exploit requires only network access to the HTTP interface, and an attacker can cause the vulnerability to take effect by tricking a user into interacting with a crafted request (UI required). Although the EPSS score is listed as < 1 %, the absence of any current exploitation reports does not negate the risk, and the vulnerability is not in CISA’s KEV list. Clients should therefore treat it as a serious security issue and apply the vendor patch promptly.

Generated by OpenCVE AI on August 2, 2026 at 21:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the Oracle WebCenter Content security patch that addresses the authorization bypass for versions 12.2.1.4.0 and 14.1.2.0.0.
  • Restrict external HTTP/S traffic to WebCenter Content to a limited set of trusted IP ranges and enforce strict firewall rules.
  • Implement application layer monitoring to detect anomalous GET/POST requests that could indicate malicious redirect attempts or unauthorized content access.

Generated by OpenCVE AI on August 2, 2026 at 21:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Control Bypass in Oracle WebCenter Content Enabling Unauthorized Data Access, Modification, and Partial Denial of Service

Tue, 28 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability Enabling Unauthorized Data Access and Partial Denial of Service in Oracle WebCenter Content

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability Enabling Unauthorized Data Access and Partial Denial of Service in Oracle WebCenter Content
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T12:56:07.019Z

Reserved: 2026-07-08T15:51:40.549Z

Link: CVE-2026-60641

cve-icon Vulnrichment

Updated: 2026-07-27T12:56:01.968Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:30:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')