Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the Content Server component of Oracle WebCenter Content and allows an attacker who can reach the HTTP interface to obtain unauthenticated access. Although successful exploitation requires the involvement of a user other than the attacker, an authenticated victim can then view, insert, update or delete content that should be restricted. The primary impact is loss of confidentiality and integrity for critical data stored within WebCenter Content.

Affected Systems

Oracle WebCenter Content, version 12.2.1.4.0 and version 14.1.2.0.0, is affected. These releases are part of Oracle Fusion Middleware and are delivered by Oracle Corporation.

Risk and Exploitability

The CVSS v3.1 score of 7.1 indicates a high severity, with high confidentiality impact and low integrity impact. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in CISA KEV. The likely attack path is remote over HTTP, with the attacker leveraging the ability to reach the content server without authentication. Attackers would need to convince a human user to perform an action that satisfies the vulnerability’s requirement for non‑attacker interaction to achieve the unauthorized data access or modification.

Generated by OpenCVE AI on August 21, 2026 at 12:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade to a fixed version of Oracle WebCenter Content.
  • Restrict network access to the Content Server by configuring firewall rules and enforcing TLS to reduce exposure via HTTP.
  • Ensure that authentication is mandatory for all exposed endpoints and disable any anonymous or public access configurations.
  • Monitor access logs for suspicious activity and implement additional verification steps (e.g., CAPTCHA) to reduce the risk of the required human interaction.

Generated by OpenCVE AI on August 21, 2026 at 12:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Access Vulnerability in Oracle WebCenter Content

Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T19:49:21.377Z

Reserved: 2026-07-08T15:52:20.745Z

Link: CVE-2026-61288

cve-icon Vulnrichment

Updated: 2026-08-20T19:34:14.978Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:58.050

Modified: 2026-08-26T17:55:05.560

Link: CVE-2026-61288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:15:05Z

Weaknesses