Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
Published: 2026-08-18
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle WebCenter Content allows a low‑privileged attacker who can reach the application over HTTP to gain unauthorized access to critical data and, with human interaction from a user who is not the attacker, obtain the ability to read, insert, update or delete content. The vulnerability is specifically a permission escalation that can result in both confidentiality and integrity impacts, but it does not affect availability. The CVE description highlights that compromise can extend to other Fusion Middleware products due to a scope change. This type of weakness is reflected by the CWE identifiers for improper use of authorization controls.

Affected Systems

The vulnerability affects Oracle Corporation's WebCenter Content product. The affected releases are version 12.2.1.4.0 and 14.1.2.0.0. Because the flaw can change scope, systems that integrate with or depend on WebCenter Content may also be impacted.

Risk and Exploitability

The CVSS v3.1 base score of 7.6 indicates a high risk. The vector shows that attackers need network access via HTTP, low authentication privileges and user interaction; no active exploitation data is available (EPSS < 1% and not listed in CISA KEV). The requirement for another user to interact means that social‑engineering or phishing tactics may be necessary. Although the exploitation is not yet known to be widely active, the combination of a high inherent severity with a low exploitation probability means that mitigation should be prioritized now to prevent possible future attacks.

Generated by OpenCVE AI on August 21, 2026 at 15:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade Oracle WebCenter Content to a version newer than 12.2.1.4.0 or 14.1.2.0.0 to resolve the privilege escalation flaw.
  • Restrict HTTP access to WebCenter Content by placing it behind a VPN or firewall that allows only trusted internal hosts, thereby limiting the attack surface.
  • Implement strict authentication and least‑privilege controls for all users of WebCenter Content and enable multi‑factor authentication where possible to reduce the risk of user‑initiated exploitation.

Generated by OpenCVE AI on August 21, 2026 at 15:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Access Privilege Escalation in Oracle WebCenter Content

Fri, 21 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Title HTTP-based Permission Escalation in Oracle WebCenter Content
Weaknesses CWE-285

Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title HTTP-based Permission Escalation in Oracle WebCenter Content
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T19:49:13.926Z

Reserved: 2026-07-08T15:51:55.601Z

Link: CVE-2026-60909

cve-icon Vulnrichment

Updated: 2026-08-20T19:29:41.349Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:47.230

Modified: 2026-08-27T18:34:36.287

Link: CVE-2026-60909

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T16:00:15Z

Weaknesses