Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebCenter Content executes to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Oracle WebCenter Content allows an attacker who already has logged onto the host system, but without authentication to the application itself, to compromise the application and gain unrestricted access to all content data stored within it. The weakness appears to be an authorization defect that bypasses normal access controls, enabling the attacker to read highly confidential data. The impact is limited to confidentiality of data; integrity and availability are not affected. The weakness aligns with improper authorization principles.

Affected Systems

Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The product is part of Oracle Fusion Middleware, and the flaw is centered on the Content Server component. The components are commonly deployed in enterprise content management environments and may interoperate with other Oracle and non-Oracle applications, so successful exploitation could compromise additional data or systems.

Risk and Exploitability

The CVSS 3.1 base score is 7.1, indicating a high risk to confidentiality. The attack requires local system access but no application credentials, so it is relatively easy to exploit for anyone who can log on to the host. The EPSS score is <1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog; however, the local nature of the attack and lack of mitigations make it a significant threat in environments where privileged access to the host is possible. An adversary could compromise the application and retrieve all stored data, potentially exposing sensitive or regulated information.

Generated by OpenCVE AI on August 21, 2026 at 12:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor's security patch for Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 to remediate the authorization flaw
  • Restrict operating-system level access to the directories and processes that run WebCenter Content, limiting exposure to only necessary service accounts
  • Enforce intrusion detection and log monitoring on the host to detect suspicious activity involving the application and its data

Generated by OpenCVE AI on August 21, 2026 at 12:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Oracle WebCenter Content Allows Unauthenticated Host Users to Retrieve All Application Data

Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebCenter Content executes to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T19:49:21.826Z

Reserved: 2026-07-08T15:52:20.745Z

Link: CVE-2026-61295

cve-icon Vulnrichment

Updated: 2026-08-20T19:34:33.109Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:58.523

Modified: 2026-08-26T17:55:31.850

Link: CVE-2026-61295

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:15:14Z

Weaknesses