Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle WebCenter Content product, part of Oracle Fusion Middleware’s Web Content Management component, has a vulnerability that allows a low‑privileged attacker with network access via HTTP to compromise the application. The vulnerability description states that successful exploitation can result in takeover of the application, and the CVSS vector indicates full confidentiality, integrity, and availability impact, which indicates that an attacker could gain full control of the target system. This interpretation is inferred from the reported impacts, as the description does not explicitly mention remote code execution.

Affected Systems

The affected versions are Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0, as listed in the July 2026 CPU advisory. These releases require HTTP connectivity for operation and are susceptible to the described flaw.

Risk and Exploitability

The CVSS base score of 8.8 reflects high severity, while an EPSS score of less than 1% suggests that, although the flaw is serious, actual exploitation is unlikely but possible; it has not been reported in the CISA KEV catalog. An attacker with low privilege who can reach the service over HTTP can exploit the vulnerability using readily available tools, potentially gaining full control of the WebCenter Content environment and compromising confidentiality, integrity, and availability.

Generated by OpenCVE AI on August 2, 2026 at 21:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebCenter Content security patch for versions 12.2.1.4.0 and 14.1.2.0.0 available from Oracle’s July 2026 CPU advisory.
  • Restrict HTTP access to the WebCenter Content instance by limiting allowed IP ranges or placing the service behind a VPN or firewall.
  • Remove or disable low‑privileged accounts that have remote access to the application, ensuring only necessary accounts remain.

Generated by OpenCVE AI on August 2, 2026 at 21:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title HTTP-Based Application Takeover Vulnerability in Oracle WebCenter Content

Thu, 30 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Low‑privileged HTTP Attack Allows Oracle WebCenter Content Takeover

Mon, 27 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Low‑privileged HTTP Attack Allows Oracle WebCenter Content Takeover

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:48.969Z

Reserved: 2026-07-08T15:51:55.575Z

Link: CVE-2026-60656

cve-icon Vulnrichment

Updated: 2026-07-24T19:29:34.450Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:30:04Z

Weaknesses