Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle WebCenter Content implements an improper access control that permits a low-privileged attacker with HTTP network access to read, insert, update or delete data beyond its intended scope. Based on the description, it is inferred that no user interaction is required, and the attacker can gain unauthorized read and modification access to confidential documents. This flaw carries a CVSS 3.1 base score of 7.1, indicating high confidentiality impact and lower integrity impact, and it includes a scope change that may affect other Oracle products linked to the content server.

Affected Systems

Vulnerable versions are Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0. These deployments are typically part of larger Oracle Fusion Middleware environments; as such, an attacker who compromises the content server could also compromise other components that rely on the same data store or services that interact with WebCenter Content.

Risk and Exploitability

The likely attack vector is HTTP network traffic from a low-privileged account, as inferred from the description. Exploitation requires only this network access and no user interaction. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating that no public exploits are known. However, the CVSS score of 7.1 and the scope change suggest the potential for significant impact if the access control weakness is present in related applications. Organizations should promptly apply the vendor patch, or if not yet available, restrict HTTP traffic to trusted IPs and review user permissions.

Generated by OpenCVE AI on August 21, 2026 at 14:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebCenter Content patch that addresses the improper access control vulnerability for both 12.2.1.4.0 and 14.1.2.0.0.
  • If the patch cannot be applied immediately, block or restrict HTTP traffic to the WebCenter Content servers using firewall or load‑balancer rules, allowing only trusted IP addresses to communicate with the service.
  • Review and tighten user roles and permissions within WebCenter Content, removing unnecessary privileges that could be leveraged by a low-privileged attacker.
  • Enable detailed audit logging and monitor for anomalous data modification attempts, alerting on repeated unauthorized access patterns.

Generated by OpenCVE AI on August 21, 2026 at 14:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle WebCenter Content Allowing Unauthorized Data Access

Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle WebCenter Content Allowing Unauthorized Data Access
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T19:49:15.539Z

Reserved: 2026-07-08T15:51:55.603Z

Link: CVE-2026-60949

cve-icon Vulnrichment

Updated: 2026-08-20T19:30:37.366Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:48.667

Modified: 2026-08-26T17:53:43.360

Link: CVE-2026-60949

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T14:30:07Z

Weaknesses