Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle WebCenter Content allows an attacker with network access via HTTP and only low privileges to gain unauthorized access to all data exposed by the product. The flaw causes a scope change, enabling the attacker to reach system‑level confidentiality impact without requiring elevated permissions. Reported on CVSS 3.1 with a base score of 7.7, the vulnerability threatens the confidentiality of critical data.

Affected Systems

Oracle WebCenter Content version 12.2.1.4.0 and 14.1.2.0.0 are affected. These releases are part of Oracle Fusion Middleware’s Content Server component.

Risk and Exploitability

The CVSS score of 7.7 indicates a high risk to confidentiality. The EPSS score of < 1% indicates a very low exploitation probability. The vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote HTTP traffic, implying that any host able to reach the WebCenter Content instance could exploit the flaw. Because the privilege requirement is low, the risk to business data is significant, especially for organizations that expose WebCenter Content over public or shared networks.

Generated by OpenCVE AI on August 21, 2026 at 13:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebCenter Content security patch as published in the Oracle security advisory
  • Restrict HTTP access to the WebCenter Content instance to trusted IP ranges or enforce VPN access
  • Enable detailed logging for authentication and data access and conduct regular log reviews for anomalous activity

Generated by OpenCVE AI on August 21, 2026 at 13:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via HTTP in Oracle WebCenter Content Leads to Scope Change

Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T19:49:16.853Z

Reserved: 2026-07-08T15:51:55.606Z

Link: CVE-2026-60983

cve-icon Vulnrichment

Updated: 2026-08-20T19:31:27.865Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:50.447

Modified: 2026-08-26T17:54:57.857

Link: CVE-2026-60983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:15:05Z

Weaknesses