Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data as well as unauthorized read access to a subset of Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle WebCenter Content product contains a vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation requires human interaction from a third party and can result in unauthorized update, insertion or deletion of data, unauthorized read access to a subset of content, and a partial denial of service. The impact spans confidentiality, integrity, and availability as defined by the CVSS v3.1 score of 7.1.

Affected Systems

Affected versions are Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0, as listed by the CNA. No other Oracle products are mentioned in the official description as directly impacted, though the CVE notes that attacks may significantly affect additional products through scope changes.

Risk and Exploitability

The CVSS score indicates a medium‑high severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an HTTP request sent over the network; the requirement of human interaction suggests a social‑engineering component. Given these factors, the risk of exploitation is moderate to high in exposed environments, and the potential impact could affect data integrity, confidentiality, and service availability.

Generated by OpenCVE AI on August 21, 2026 at 04:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade as detailed in the official security advisory to fix the vulnerability.
  • Restrict HTTP access to Oracle WebCenter Content to trusted networks or implement firewall rules to block inbound traffic from untrusted sources.
  • Disable or restrict any unused HTTP endpoints or services exposed by WebCenter Content that are not required for business operations.
  • Monitor access logs for anomalous activity that might indicate attempts to leverage this vulnerability and investigate promptly.

Generated by OpenCVE AI on August 21, 2026 at 04:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote HTTP Vulnerability Allowing Unauthorized Data Modification in Oracle WebCenter Content

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote HTTP Vulnerability Allowing Unauthorized Data Modification in Oracle WebCenter Content
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data as well as unauthorized read access to a subset of Oracle WebCenter Content accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Content. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:10.839Z

Reserved: 2026-08-04T22:06:34.602Z

Link: CVE-2026-70858

cve-icon Vulnrichment

Updated: 2026-08-19T12:10:36.938Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:41.987

Modified: 2026-08-26T17:55:52.093

Link: CVE-2026-70858

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T04:30:09Z

Weaknesses