Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability grants an unauthenticated attacker, with network access via HTTP, the ability to create, delete, or modify data within Oracle WebCenter Content. The attacker could also gain complete unauthorized access to all data the application can reach, leading to significant confidentiality and integrity compromises. The weakness allows the attacker to bypass authentication controls, causing a direct breach of data protection safeguards.

Affected Systems

Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected, as noted by the vendor alert.

Risk and Exploitability

The CVSS 3.1 base score of 9.1 highlights the high severity of this flaw, and the ease of exploitation is amplified by the lack of required privileges. The EPSS score of less than 1% suggests that large‑scale exploitation is currently unlikely, yet the flaw is still highly critical. When combined with active network exposure via HTTP, an attacker can immediately exploit the weakness to compromise confidential data. The vulnerability is not listed as a known exploited vulnerability in CISA KEV, but the potential impact remains substantial.

Generated by OpenCVE AI on August 4, 2026 at 03:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch or update released by Oracle in the cited security advisory
  • If a patch cannot be applied immediately, restrict or block HTTP access to WebCenter Content from untrusted networks
  • Disable or secure the default HTTP interface to enforce HTTPS and remove unnecessary service exposure
  • Apply URL filtering or web‑application firewall rules to block suspicious request patterns

Generated by OpenCVE AI on August 4, 2026 at 03:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Manipulation in Oracle WebCenter Content

Thu, 30 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Manipulation in Oracle WebCenter Content

Tue, 28 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote Unauthorized Access and Data Manipulation via WebCenter Content HTTP Interface
Weaknesses CWE-287

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Remote Unauthorized Access and Data Manipulation via WebCenter Content HTTP Interface
Weaknesses CWE-284
CWE-287

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:42.887Z

Reserved: 2026-07-08T15:51:55.575Z

Link: CVE-2026-60649

cve-icon Vulnrichment

Updated: 2026-07-27T12:45:19.565Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:15:03Z

Weaknesses