Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An easily exploitable flaw in Oracle WebCenter Content’s Web Content Management component allows a low‑privileged attacker with network access over HTTP to compromise the application. Successful exploitation can affect confidentiality, integrity, and availability, ultimately enabling a remote attacker to take complete control of the affected system. The vulnerability grants low privilege but the impact expands to the entire application, and, because the scope of the vulnerability changes, other products within the environment may also be at risk.

Affected Systems

Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected.

Risk and Exploitability

The CVSS base score of 9.9 indicates critical severity. The EPSS score of less than 1% shows that active exploitation is currently rare, but the attack can be carried out remotely via standard HTTP traffic, requiring no special privileges. The vulnerability is not listed in CISA’s KEV catalog, yet the high impact and remote nature warrant immediate attention. The likely attack vector is an unauthenticated or minimally privileged HTTP request to the WebCenter Content service, enabling full takeover after exploitation.

Generated by OpenCVE AI on August 2, 2026 at 21:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch or upgrade to the latest Oracle WebCenter Content release that addresses the improper access control weakness identified as CWE-284, as outlined in the Oracle CPU advisory.
  • Configure and enforce least privilege role‑based access controls for WebCenter Content services to mitigate the improper privilege management issue (CWE-269), ensuring that users have only the permissions necessary for their tasks.
  • Restrict inbound HTTP traffic to trusted IP addresses or internal networks using firewall rules or VPNs to limit exposure of the vulnerable interfaces, thereby reducing the opportunity for remote exploitation.
  • Audit and disable any unused administrative web interfaces or services to reduce the attack surface, addressing potential direct web input vulnerabilities (CWE-863) by eliminating unnecessary entry points.

Generated by OpenCVE AI on August 2, 2026 at 21:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Remote HTTP Exploitation Enables Full Takeover of Oracle WebCenter Content

Mon, 27 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Remote HTTP Exploit Enables Full Takeover of Oracle WebCenter Content
Weaknesses CWE-287

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-863
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Remote HTTP Exploit Enables Full Takeover of Oracle WebCenter Content
Weaknesses CWE-284
CWE-287

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:51.553Z

Reserved: 2026-07-08T15:51:55.576Z

Link: CVE-2026-60663

cve-icon Vulnrichment

Updated: 2026-07-24T19:22:51.770Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:30:04Z

Weaknesses