Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle WebCenter Content executes to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in Oracle WebCenter Content’s Content Server component that allows an unauthenticated attacker with physical network connectivity to the host machine to create, delete or modify critical data and gain unauthorized access to all data stored by the application. The flaw impacts confidentiality and integrity, enabling the attacker to alter or destroy content without authentication.

Affected Systems

Affected are Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is specific to the Oracle Fusion Middleware stack that hosts the Content Server.

Risk and Exploitability

The CVSS v3.1 base score is 8.0, indicating high severity, while the attack vector is local (adjacency). The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the exploitation requires physical or local network access, the likelihood of attack is limited to environments with compromised LAN segments or insider threat scenarios, but once achieved the attacker can permanently alter or exfiltrate critical data.

Generated by OpenCVE AI on August 18, 2026 at 23:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Oracle WebCenter Content patch for versions 12.2.1.4.0 and 14.1.2.0.0 as published in the Oracle Security Alert
  • Restrict physical and network access to the internal segments that directly communicate with the WebCenter Content servers, allowing only trusted devices and personnel
  • After applying the patch, perform a verification scan to confirm the vulnerability is remediated and monitor logs for any anomalous write or delete activity on critical data repositories
  • Configure a firewall or network segmentation policy to block unnecessary inbound connections to the WebCenter Content servers, reducing the footprint of the local communication segment

Generated by OpenCVE AI on August 18, 2026 at 23:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Network Attack Allows Unauthorized Data Modification in Oracle WebCenter Content
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle WebCenter Content executes to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:25.429Z

Reserved: 2026-07-08T15:51:55.604Z

Link: CVE-2026-60961

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:49.270

Modified: 2026-08-18T21:16:49.270

Link: CVE-2026-60961

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:30:04Z

Weaknesses