Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in Oracle WebCenter Content's Content Server component allows an unauthenticated attacker with network access via HTTP to compromise the application. The weakness involves Cross‑Site Request Forgery (CWE‑352), Open Redirect (CWE‑601), and Cross‑Site Scripting (CWE‑79). An attacker does not need to authenticate, but a human interaction from a person other than the attacker is required to complete the attack. If successful, the attacker can take control of the Oracle WebCenter Content system, leading to loss of confidentiality, integrity, and availability. The CVSS 3.1 score of 8.8 reflects these severe impacts, with the vector indicating a network attack, low complexity, no privileges required, user interaction required, and scope unchanged.

Affected Systems

Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware, are affected. These versions are deployed in enterprise content management environments, and the vulnerability applies to the Content Server component accessed through HTTP endpoints.

Risk and Exploitability

The high CVSS score indicates significant risk, while the EPSS score of less than 1 % suggests that exploitation has not yet been widely observed. The vulnerability is not listed in the CISA KEV catalog. Because the attack requires a user to interact with the application—such as clicking a malicious link—an attacker may rely on social engineering to gain a foothold. Once the user interacts and the vulnerability is triggered, the attacker can gain full control of the application with no authentication, resulting in a complete system takeover.

Generated by OpenCVE AI on August 4, 2026 at 16:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle WebCenter Content patches released in the July 2026 CPU advisory to remediate the vulnerability.
  • Configure firewalls or access control lists to restrict external HTTP access to the Content Server and limit it to trusted networks or VPN reach.
  • Enable detailed logging for HTTP traffic to the Content Server and monitor log files for indicators of exploitation attempts, such as unexpected POST requests or unauthorized login attempts.

Generated by OpenCVE AI on August 4, 2026 at 16:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-to-Content Server Exploit Allows System Takeover

Thu, 30 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-to-Content Server Exploit Allows System Takeover

Tue, 28 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Allows Takeover of Oracle WebCenter Content
Weaknesses CWE-287
CWE-306

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
CWE-601
CWE-79
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Allows Takeover of Oracle WebCenter Content
Weaknesses CWE-287
CWE-306

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:53.034Z

Reserved: 2026-07-08T15:51:55.576Z

Link: CVE-2026-60664

cve-icon Vulnrichment

Updated: 2026-07-24T19:22:02.027Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:00:13Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')