Impact
The Oracle WebCenter Content product, part of Oracle Fusion Middleware’s Web Content Management component, has a vulnerability that allows a low‑privileged attacker with network access via HTTP to compromise the application. The vulnerability description states that successful exploitation can result in takeover of the application, and the CVSS vector indicates full confidentiality, integrity, and availability impact, which indicates that an attacker could gain full control of the target system. This interpretation is inferred from the reported impacts, as the description does not explicitly mention remote code execution.
Affected Systems
The affected versions are Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0, as listed in the July 2026 CPU advisory. These releases require HTTP connectivity for operation and are susceptible to the described flaw.
Risk and Exploitability
The CVSS base score of 8.8 reflects high severity, while an EPSS score of less than 1% suggests that, although the flaw is serious, actual exploitation is unlikely but possible; it has not been reported in the CISA KEV catalog. An attacker with low privilege who can reach the service over HTTP can exploit the vulnerability using readily available tools, potentially gaining full control of the WebCenter Content environment and compromising confidentiality, integrity, and availability.
OpenCVE Enrichment