Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle WebCenter Content executes to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a local privilege exploitation that allows a user with low-privileged access to bypass application access controls in Oracle WebCenter Content 14.1.2.0.0. Attackers can create, delete, or modify critical data, resulting in confidentiality and integrity loss. The weakness relates to insufficient authorization controls, matching CWE-284.

Affected Systems

Oracle WebCenter Content version 14.1.2.0.0, part of Oracle Fusion Middleware, is impacted. Users running this version on any infrastructure where local login access is available are at risk.

Risk and Exploitability

The CVSS 3.1 base score of 8.4 reflects a high severity. Exploitation requires local OS access with low privileged credentials and does not need user interaction, making it relatively easy to achieve in environments with shared or uncontrolled hosts. The EPSS score is extremely low, at less than 1%, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the combination of high impact and ease of local exploitation warrants immediate attention.

Generated by OpenCVE AI on August 21, 2026 at 13:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch referenced in the August 2026 security advisory.
  • Limit local login rights for infrastructure accounts that can access Oracle WebCenter Content, ensuring only trusted administrators have such access.
  • Deploy network segmentation so that only authorized, isolated hosts run Oracle WebCenter Content, reducing the risk from local attackers.
  • Enable and monitor auditing for data creation, deletion, or modification actions within WebCenter Content, and set alerts for anomalous activity.

Generated by OpenCVE AI on August 21, 2026 at 13:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Title Local Privileged Compromise Enables Unauthorized Data Modification in Oracle WebCenter Content

Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle WebCenter Content executes to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T19:49:14.297Z

Reserved: 2026-07-08T15:51:55.602Z

Link: CVE-2026-60928

cve-icon Vulnrichment

Updated: 2026-08-20T19:29:53.699Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:47.840

Modified: 2026-08-27T18:34:31.713

Link: CVE-2026-60928

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T14:00:13Z

Weaknesses