Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged attacker who can reach Oracle WebCenter Content over HTTP can exploit a set of vulnerabilities—including cross‑site request forgery, open redirect, path traversal, and cross‑site scripting—to gain full control of the application. Successful exploitation requires that a separate user act on the attacker’s behalf, committing a user interaction to complete the attack. If the exploit succeeds, the attacker can read, modify, or delete content, tamper with configuration, and disrupt availability, thereby compromising confidentiality, integrity, and availability of the entire content management system.

Affected Systems

Oracle WebCenter Content version 12.2.1.4.0 and 14.1.2.0.0, components of Oracle Fusion Middleware that provide enterprise web content management, are affected.

Risk and Exploitability

The CVSS base score of 8.0 indicates high severity. An EPSS score of less than 1 % suggests a low probability of widespread exploitation at this time, and the vulnerability is not listed in CISA KEV. The likely attack vector is an HTTP request from a low‑privileged user; the attacker must persuade or prompt another user to carry out an action that completes the exploitation process. Given the high potential impact, affected deployments face a significant risk.

Generated by OpenCVE AI on August 4, 2026 at 03:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle WebCenter Content patch released in the July 2026 Security Alert
  • Restrict unauthenticated or low‑privileged HTTP access to the application and enforce strict role‑based access controls
  • Mitigate the identified vulnerability classes by implementing anti‑CSRF tokens for state‑changing requests, validating redirect targets, restricting path traversal, and ensuring output is properly encoded to prevent cross‑site scripting

Generated by OpenCVE AI on August 4, 2026 at 03:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Enabling Takeover of Oracle WebCenter Content
Weaknesses CWE-284
CWE-287

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
CWE-601
CWE-640
CWE-79
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Enabling Takeover of Oracle WebCenter Content
Weaknesses CWE-284
CWE-287

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:35.694Z

Reserved: 2026-07-08T15:51:55.574Z

Link: CVE-2026-60646

cve-icon Vulnrichment

Updated: 2026-07-27T12:48:14.041Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:30:03Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')

  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')