Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE details an unauthenticated web access vulnerability in Oracle WebCenter Content that allows an attacker with normal HTTP network access to take over the application. The flaw is due to insufficient privilege verification (CWE‑306), which lets remote attackers act as a privileged user without authenticating. Successful exploitation results in complete compromise of confidentiality, integrity, and availability for the affected instance.

Affected Systems

Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These releases are part of the Oracle Fusion Middleware suite and are commonly deployed in enterprise content management environments. Based on the description, it is inferred that attacks may significantly impact additional products because the vulnerability can change scope within the same environment.

Risk and Exploitability

The CVSS score of 10.0 marks this vulnerability as critical, while the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is easily exploitable, requiring only unauthenticated HTTP requests to the affected instance. Because it is not listed in the CISA KEV catalog, the risk assessment relies on the severity and exploitability metrics. Attackers can achieve full takeover of the WebCenter instance, making aggressive mitigation imperative.

Generated by OpenCVE AI on August 2, 2026 at 21:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch or update released in Oracle CPU July 2026 to remove the vulnerability.
  • Restrict HTTP access to the WebCenter Content instance to trusted networks or VPNs, and enforce HTTPS so that unauthenticated requests are blocked.
  • Continuously monitor logs for anomalous requests or intrusion attempts, and investigate any signs of compromise promptly.

Generated by OpenCVE AI on August 2, 2026 at 21:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Enables Full Compromise of Oracle WebCenter Content

Thu, 30 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Remote Takeover of Oracle WebCenter Content
Weaknesses CWE-200
CWE-284

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Remote Takeover of Oracle WebCenter Content
Weaknesses CWE-200
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:34.068Z

Reserved: 2026-07-08T15:51:55.574Z

Link: CVE-2026-60644

cve-icon Vulnrichment

Updated: 2026-07-27T12:58:56.404Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:30:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function