Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Oracle WebCenter Content component Content Server permits an unauthenticated attacker who can reach the service over HTTP to bypass built‑ access controls and create, delete, or modify critical data. The flaw enables an attacker to gain unauthorized read access to all data managed by the WebCenter Content installation, thereby affecting both confidentiality and integrity. No authentication, no user interaction, and no privilege requirement are required, which means any external host can launch an exploit over the network.

Affected Systems

Oracle WebCenter Content, a product of Oracle Corporation, is affected in the versions 12.2.1.4.0 and 14.1.2.0.0. Users running either of these releases, or any product that incorporates these components, are at risk.

Risk and Exploitability

The CVSS 3.1 score of 8.7 reflects a high severity with a scope change; the vector AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N indicates an unauthenticated, remote attack that does not require user interaction. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog, but the high impact and broad exposure suggest that exploitation is possible and could compromise an organization’s data layer. The scope change warns that compromise of the WebCenter Content instance may allow an attacker to affect additional software components within the Oracle Fusion Middleware stack.

Generated by OpenCVE AI on August 18, 2026 at 23:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch that addresses this vulnerability in versions 12.2.1.4.0 and 14.1.2.0.0 as described in the Oracle security alert
  • Restrict HTTP access to the WebCenter Content server using firewalls, VLANs, or VPNs so that only trusted networks can reach the service
  • Enable application and network monitoring to detect anomalous API or HTTP requests that may indicate an exploitation attempt

Generated by OpenCVE AI on August 18, 2026 at 23:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification in Oracle WebCenter Content
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:22.150Z

Reserved: 2026-07-08T15:51:55.602Z

Link: CVE-2026-60934

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:48.087

Modified: 2026-08-18T21:16:48.087

Link: CVE-2026-60934

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:30:04Z

Weaknesses