Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle WebCenter Content allows a low‑privileged attacker who can reach the application over HTTP to create, delete, or modify data that is normally protected. As a result, confidential data can be compromised and the integrity of content stored in the system can be altered, potentially leading to loss of critical information or service disruption. The weakness is classified as an improper access control flaw.

Affected Systems

Affected versions are Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0. The product is part of Oracle Fusion Middleware and is deployed by organizations that provide web‑based document management and collaboration services.

Risk and Exploitability

The CVSS v3.1 base score of 7.7 indicates a high severity with significant confidentiality and integrity impacts. The EPSS score is less than 1%, suggesting a very low probability of exploitation in the wild at this time, and it is not listed in CISA’s KEV catalog. Successful exploitation, however, requires network access to the HTTP port of WebCenter Content and a secondary action from a user other than the attacker, implying that human interaction or social engineering may be needed. If achieved, the attacker gains unauthorized access to sensitive data and can modify or delete critical information, potentially compromising other connected products due to the scope change indicated by the CVSS vector.

Generated by OpenCVE AI on August 4, 2026 at 03:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch for Oracle WebCenter Content 12.2.1.4.0 or 14.1.2.0.0, whichever corresponds to your environment.
  • Restrict inbound network traffic to the WebCenter Content HTTP/HTTPS ports to only trusted networks and apply firewall rules to limit exposure to low‑privileged devices.
  • Review and enforce least‑privilege access controls for all user accounts interacting with WebCenter Content, ensuring that only authorized users have permissions for content creation or modification.
  • Enable application logs for all CRUD operations and periodically audit logs for anomalous activity indicating potential misuse of privileges.

Generated by OpenCVE AI on August 4, 2026 at 03:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low-Privilege Access in Oracle WebCenter Content

Thu, 30 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low-Privilege Access in Oracle WebCenter Content

Wed, 29 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low Privileged Attacker Can Compromise Oracle WebCenter Content via HTTP – Unauthorized Data Modification

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Low Privileged Attacker Can Compromise Oracle WebCenter Content via HTTP – Unauthorized Data Modification
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T19:26:41.653Z

Reserved: 2026-07-08T15:51:55.575Z

Link: CVE-2026-60657

cve-icon Vulnrichment

Updated: 2026-07-24T19:30:26.572Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:15:03Z

Weaknesses