Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability, identified as a CWE-284 Improper Access Control flaw, permits an unauthenticated attacker with network access to HTTP to compromise Oracle WebCenter Content. Successful exploitation allows the attacker to create, delete, or modify critical data and to gain full unauthorized access to all data that the product hosts. The vulnerability may also affect other Oracle Fusion Middleware components because the scope can change.

Affected Systems

Oracle WebCenter Content version 12.2.1.4.0 and version 14.1.2.0.0 are affected.

Risk and Exploitability

The CVSS score of 8.7 classifies this as a high‑impact vulnerability. The exploit requires only network access and does not need user interaction. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in KEV, suggesting it is not currently known to be actively exploited in the wild. However, the high severity and unauthenticated nature warrant close attention.

Generated by OpenCVE AI on August 21, 2026 at 15:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch released in the August 2026 security alert for Oracle WebCenter Content.
  • Upgrade the product to the latest patched release of Oracle WebCenter Content.
  • Restrict HTTP access to the WebCenter Content instance to trusted networks using firewalls or IP allowlists.
  • If a patch cannot be applied immediately, enable authentication (e.g., basic auth) or disable the publicly exposed endpoints until the update is deployed.

Generated by OpenCVE AI on August 21, 2026 at 15:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability Allowing Data Manipulation in Oracle WebCenter Content

Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability Allowing Data Manipulation in Oracle WebCenter Content
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T03:56:23.292Z

Reserved: 2026-07-08T15:51:55.600Z

Link: CVE-2026-60903

cve-icon Vulnrichment

Updated: 2026-08-20T19:29:29.116Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:46.877

Modified: 2026-08-27T18:33:32.110

Link: CVE-2026-60903

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T16:00:15Z

Weaknesses