Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Oracle WebCenter Content’s Web Content Management component allows an attacker with low privileges and network access via HTTP to compromise the application. The flaw is exploitable through an unauthenticated or low‑privilege path and requires the cooperation of a user not controlled by the attacker. The weakness is rooted in improper input validation (CWE‑20), lack of transport‑layer security (CWE‑295), cross‑site request forgery (CWE‑352), open redirect (CWE‑601), and misconfigured file‑path handling (CWE‑640). If successfully exploited, the attacker can take over the entire WebCenter Content instance, gaining complete control over its data and services, which results in substantial confidentiality, integrity, and availability damage.

Affected Systems

The affected products are Oracle WebCenter Content, version 12.2.1.4.0 and 14.1.2.0.0, which are part of Oracle Fusion Middleware. No additional vendor or product variants are listed. Organisations using either of these releases must investigate whether they host the vulnerable component.

Risk and Exploitability

The CVSS score of 8.0 reflects significant risk while the EPSS score of less than 1% indicates a low current exploitation probability. The vulnerability is not listed in CISA KEV. The attack vector is over the network via HTTP, and although it requires human interaction, a single compromised user can enable a full takeover, making it a high‑risk threat for businesses that expose their WebCenter Content interfaces to the internet.

Generated by OpenCVE AI on August 4, 2026 at 03:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle WebCenter Content patch released in the CPU Jul 2026 advisory to the affected versions 12.2.1.4.0 and 14.1.2.0.0
  • Restrict HTTP access to the WebCenter Content instance by enforcing network segmentation or firewall rules so that only trusted internal networks can reach the application
  • Configure the application to enforce strict access controls on privileged functions, ensuring that low‑privilege users cannot trigger sensitive operations

Generated by OpenCVE AI on August 4, 2026 at 03:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Remote WebCenter Content Compromise via Low-Privilege HTTP Access

Thu, 30 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Enables Full Application Takeover
Weaknesses CWE-285
CWE-862

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-295
CWE-352
CWE-601
CWE-640
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Enables Full Application Takeover
Weaknesses CWE-285
CWE-862

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:36.549Z

Reserved: 2026-07-08T15:51:55.575Z

Link: CVE-2026-60648

cve-icon Vulnrichment

Updated: 2026-07-27T12:46:35.320Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:30:03Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-295

    Improper Certificate Validation

  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')

  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password