HIGH 8.4

CVE-2026-46788: Oracle WebCenter Content Administrative Access Control Vulnerability

A vulnerability in Oracle WebCenter Content version 14.1.2.0.0 allows an attacker with administrative privileges to compromise the system through specially crafted HTTP requests. The vulnerability requires an administrator to interact with malicious content, but once exploited, can lead to complete control of the WebCenter Content instance. Because WebCenter Content often integrates with other enterprise systems, a successful attack may cascade to affect additional products in your Oracle Fusion Middleware environment.

Source data · NVD / CISA · public domain

CVSS
3.1 · 8.4 HIGH · CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Weaknesses (CWE)
CWE-284
Affected products
1 configuration(s)
Published / Modified
2026-06-17 / 2026-06-19

NVD description (verbatim)

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H).

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

This improper access control vulnerability (CWE-284) exists in the Content Server component of Oracle WebCenter Content. The attack vector is network-based with low complexity, requiring high-level privileges and user interaction (an administrator must perform an action). The scope is changed, meaning the vulnerability can impact resources beyond the vulnerable component. An attacker positioned with administrator credentials can craft HTTP requests that bypass authorization controls, resulting in full confidentiality, integrity, and availability compromise of the affected system.

Business impact

Successful exploitation enables an attacker to take complete control of your Oracle WebCenter Content repository, potentially exposing sensitive documents, modifying content classifications, and disrupting content management workflows. Because WebCenter Content typically serves as a centralized repository for enterprise documents and integrates with other Oracle middleware components, the blast radius extends beyond the WebCenter instance itself. This could affect compliance with document retention policies, business continuity for content-dependent processes, and confidentiality of classified or regulated information stored in the repository.

Affected systems

Oracle WebCenter Content version 14.1.2.0.0 is confirmed affected. Organizations running this version with administrators who access the system over network connections are directly at risk. Check your deployment inventory to identify all instances, including development and test environments, as those are often overlooked. The vulnerability does not affect later major versions, but verify your exact patch level against Oracle's advisory, as minor version differences may matter.

Exploitability

While the vulnerability has a network attack vector and low attack complexity, practical exploitation is constrained by the requirement for high-privilege (administrator) access and user interaction. This is not a vulnerability that random internet traffic will trigger. However, if you have hostile insiders, compromised administrator accounts, or if an attacker has gained initial access to your network and can trick an admin into clicking a malicious link, exploitation becomes realistic. The ease of exploitation is rated as 'easily exploitable' by CVSS logic, but real-world risk depends on your administrative security controls.

Remediation

Oracle will provide a patch for version 14.1.2.0.0; check Oracle's Critical Patch Update advisories for the available patch version and deployment timeline. Until patching is possible, implement network segmentation to restrict WebCenter Content access to trusted internal networks only, enforce multi-factor authentication for all administrative accounts, monitor Content Server logs for suspicious HTTP requests with high-privilege actions, and audit recent administrator activity for unauthorized changes. Do not expose WebCenter Content directly to the internet.

Patch guidance

Obtain the latest security patch from Oracle through their Critical Patch Update process. Test the patch thoroughly in a non-production environment first, as WebCenter Content patches can require application server restarts and may affect dependent integrations. Verify that your version 14.1.2.0.0 deployment is actually in scope for the patch release (Oracle sometimes restricts patches to specific version branches). After patching, confirm through Oracle's advisory documentation that the specific CVE-2026-46788 fix is included in your patch version.

Detection guidance

Monitor Content Server HTTP access logs for unusual administrative actions, particularly those involving unexpected PUT, POST, or DELETE requests to sensitive endpoints. Look for administrator sessions that deviate from normal behavior patterns. Enable audit logging on the Content Server component if not already active, and review logs for privilege escalation or unauthorized role assignments. Network-based detection should flag any HTTP requests to WebCenter Content from unexpected source IPs or with suspicious parameter values. Correlation with your identity provider logs can identify compromised or misused administrator accounts.

Why prioritize this

Although this vulnerability requires an attacker to possess administrative credentials and trigger user interaction, the impact scope is severe (full system compromise with effects on downstream systems) and the ease of exploitation is rated as 'easily exploitable' under CVSS methodology. For organizations running 14.1.2.0.0 in production, where WebCenter Content holds business-critical or sensitive information, patching should be prioritized within your standard security patch cycle—likely within 30 days. If you use administrative accounts for day-to-day content work, raise the priority further and implement compensating controls immediately.

Risk score, explained

The CVSS 3.1 score of 8.4 (HIGH) reflects full impact across confidentiality, integrity, and availability; a network-accessible component; and a changed scope that can affect other systems. The score is tempered slightly by the requirement for high-level privileges and human interaction, which narrows the attacker population. However, in environments where administrator account compromise is a realistic threat vector, this is a critical finding that warrants immediate attention.

Frequently asked questions

Do we need to patch if WebCenter Content is only accessed internally?

Yes. While network isolation reduces risk, the vulnerability still requires patching because the requirement for admin privileges doesn't eliminate the threat of insider attacks, compromised admin accounts, or lateral movement from another breach. Internal-only access is a compensating control, not a substitute for patching.

Can we temporarily disable administrator access to reduce risk?

Disabling all administrative access will prevent the system from being managed or updated, which creates operational risk. Instead, restrict administrative access to specific trusted networks or jump hosts, enforce MFA, and enable detailed logging. These are interim measures while you prepare patching.

Does this vulnerability affect Oracle Content Management (OCM) or other Oracle products?

This CVE is specific to Oracle WebCenter Content version 14.1.2.0.0. Different Oracle content products have different vulnerability profiles. Check the CVE's affected products list and cross-reference your deployment. If you run multiple Oracle middleware products, each should be assessed independently.

What is CWE-284 and why is it serious in this context?

CWE-284 is improper access control—the system fails to properly verify that an administrator should be allowed to perform a specific action. In a repository system like WebCenter Content, broken access controls can expose all stored documents and allow unauthorized modifications to critical business information.

This analysis is based on Oracle's official CVE description and CVSS scoring. Patch availability, version applicability, and remediation timelines should be verified directly with Oracle's security advisories and your internal change management processes. The vulnerability classification, affected versions, and scoring may be updated by Oracle; reference the official CVE entry and Oracle Critical Patch Update bulletins as your authoritative source. This assessment does not constitute legal or compliance advice; consult your risk and compliance teams regarding regulatory implications for your specific environment. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).