Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Low‑privileged attackers with network access over HTTP can exploit this Oracle WebCenter Content flaw to achieve a full takeover of the application, compromising confidentiality, integrity, and availability. The vulnerability requires a secondary user, other than the attacker, to perform an action that triggers the exploit. The weakness is a Cross‑Site Request Forgery (CWE‑352), allowing an attacker to forge requests on behalf of the victim and execute privileged operations leading to full control of the content server.

Affected Systems

Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware, are affected by this flaw.

Risk and Exploitability

The flaw is rated with a CVSS 3.1 base score of 8.0, indicating a high severity with significant confidentiality, integrity, and availability impact. The EPSS score is below 1 %, suggesting a low probability of exploitation in the near term, and the vulnerability is not listed in the CISA KEV catalog. Exploitation can occur over the network via HTTP, and it relies on user interaction from a non‑attacker. An attacker can prepare a malicious request and convince a legitimate user to trigger it, leading to full control of the WebCenter Content instance. While no public exploits are known, the high impact warrants prompt attention.

Generated by OpenCVE AI on August 4, 2026 at 03:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebCenter Content security updates for versions 12.2.1.4.0 and 14.1.2.0.0 as documented in the Oracle security alert
  • Restrict external HTTP traffic to the WebCenter Content server with firewalls or network segmentation, limiting access to trusted networks
  • Enforce strict authentication and authorization policies, and review user permissions to prevent privilege escalation

Generated by OpenCVE AI on August 4, 2026 at 03:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery in Oracle WebCenter Content Allows Full Application Takeover

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery in Oracle WebCenter Content Allows Full Application Takeover

Tue, 28 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploitation Leading to Full Takeover of Oracle WebCenter Content
Weaknesses CWE-285

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploitation Leading to Full Takeover of Oracle WebCenter Content
Weaknesses CWE-285
CWE-352

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:32.558Z

Reserved: 2026-07-08T15:51:55.574Z

Link: CVE-2026-60643

cve-icon Vulnrichment

Updated: 2026-07-27T12:58:13.946Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:30:03Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)