Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low-privileged attacker who can reach the service over HTTP can exploit an issue in Oracle WebCenter Content that relates to CWE-20 (Improper Input Validation), CWE-352 (Cross‑Site Request Forgery), CWE-601 (Open Redirect), CWE-640 (Improper Authentication), and CWE-79 (Cross‑Site Scripting). The vulnerability requires cooperation from another user, indicating a social engineering or phishing vector. Successful exploitation results in full control of the application, giving the attacker unrestricted access to all data and administrative functions, thereby compromising confidentiality, integrity, and availability.

Affected Systems

Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected.

Risk and Exploitability

The CVSS 3.1 base score of 8.0 rates the vulnerability as high severity. The weakness corresponds to CWE-20, CWE-352, CWE-601, CWE-640, and CWE-79, enabling improper input validation, cross‑site request forgery, open redirect, improper authentication, and cross‑site scripting that facilitate the attack. The EPSS score of less than 1% indicates that exploitation attempts have been rare to date, and the vulnerability is not listed in the CISA KEV catalog. Attackers need only network access to the HTTP interface and the cooperation of another user, which makes the exploitation straightforward from a remote environment that can reach the application gateway.

Generated by OpenCVE AI on August 4, 2026 at 16:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch for WebCenter Content that addresses this issue
  • Restrict HTTP access to Oracle WebCenter Content to trusted IP addresses only, blocking untrusted traffic
  • Implement a Web Application Firewall or security rules to detect and block anomalous requests targeting the affected endpoints

Generated by OpenCVE AI on August 4, 2026 at 16:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Exploit with Human Interaction Enables Full Application Takeover in Oracle WebCenter Content

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Exploit with Human Interaction Enables Full Application Takeover in Oracle WebCenter Content

Thu, 30 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via HTTP in Oracle WebCenter Content Leading to Takeover
Weaknesses CWE-284

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-352
CWE-601
CWE-640
CWE-79
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via HTTP in Oracle WebCenter Content Leading to Takeover
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:43.619Z

Reserved: 2026-07-08T15:51:55.575Z

Link: CVE-2026-60650

cve-icon Vulnrichment

Updated: 2026-07-27T12:41:39.380Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:00:13Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')

  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')