Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a low‑privileged attacker with network access via HTTP to take full control of Oracle WebCenter Content, affecting confidentiality, integrity and availability. This flaw is due to an improper authorization mechanism that permits unauthorized users to perform privileged actions, classified as a high‑severity remote takeover. The potential impact includes data exposure, modification, and denial of service for all content managed through the application.

Affected Systems

Oracle Corporation’s WebCenter Content product versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These versions are part of Oracle Fusion Middleware and are used by organizations to manage web content. The flaw exists in the Web Content Management component, and any deployment of the specified versions is vulnerable.

Risk and Exploitability

The CVSS v3.1 score of 8.8 indicates a high level of risk, while the EPSS score of less than 1% shows a low probability of exploitation. It is not listed in the CISA KEV catalog, but attackers could exploit this weakness over standard HTTP connections, requiring only low privileges to succeed. Successful exploitation would grant an attacker complete takeover of the application.

Generated by OpenCVE AI on August 4, 2026 at 03:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebCenter Content patch or upgrade to an unaffected version as provided in the Oracle security update.
  • Restrict external HTTP access to the WebCenter Content administrative interfaces by using firewalls or subnet isolation, limiting exposure to trusted networks.
  • Enforce strict authentication and role‑based authorization per Oracle’s security hardening guidelines, ensuring that only privileged users can access management functions.

Generated by OpenCVE AI on August 4, 2026 at 03:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Remote Authorization Bypass in Oracle WebCenter Content Allows Full Application Compromise

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Remote Authorization Bypass in Oracle WebCenter Content Allows Full Application Compromise

Tue, 28 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote Takeover of Oracle WebCenter Content via Low-Privileged HTTP Access
Weaknesses CWE-285

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover of Oracle WebCenter Content via Low-Privileged HTTP Access
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:48.207Z

Reserved: 2026-07-08T15:51:55.575Z

Link: CVE-2026-60655

cve-icon Vulnrichment

Updated: 2026-07-24T19:28:48.052Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:15:03Z

Weaknesses