Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in Oracle WebCenter Content and allows a low‑privileged attacker with network access via HTTP to bypass access controls and obtain unauthorized access to sensitive data or all accessible content. Successful exploitation can also cause a partial denial of service, degrading availability. The CVSS 3.1 Base Score of 7.1 reflects a high confidentiality impact and a low availability impact.

Affected Systems

Affected products are Oracle WebCenter Content, part of Oracle Fusion Middleware under the Web Content Management component. The versions impacted are 12.2.1.4.0 and 14.1.2.0.0. No other product versions are listed as affected.

Risk and Exploitability

The CVSS score indicates a high severity risk, while the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not yet listed in the CISA KEV catalog. Exploitation requires only low‑privilege network access to the WebCenter Content HTTP interfaces, making the attack vector network‑based and relatively easy to launch.

Generated by OpenCVE AI on August 2, 2026 at 21:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply the latest security patch for Oracle WebCenter Content from the Oracle CPU July 2026 advisory.
  • If immediate patching is not possible, limit HTTP access to WebCenter Content to trusted IP addresses using firewall or web application firewall rules.
  • Implement network segmentation and monitor suspicious HTTP traffic for signs of exploitation attempts.

Generated by OpenCVE AI on August 2, 2026 at 21:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Oracle WebCenter Content Unauthorized Data Access and Service Disruption Vulnerability

Tue, 28 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Partial Denial of Service via Low Privilege HTTP Requests in Oracle WebCenter Content

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 26 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Partial Denial of Service via Low Privilege HTTP Requests in Oracle WebCenter Content

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T12:47:17.612Z

Reserved: 2026-07-08T15:51:55.574Z

Link: CVE-2026-60647

cve-icon Vulnrichment

Updated: 2026-07-27T12:47:13.862Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:30:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control

  • CWE-400

    Uncontrolled Resource Consumption