MEDIUM 5.3

CVE-2026-46790: Oracle WebCenter Content Unauthenticated Information Disclosure Vulnerability

Oracle WebCenter Content version 14.1.2.0.0 contains an information disclosure vulnerability that allows an unauthenticated attacker to read sensitive data over the network without requiring credentials or user interaction. The vulnerability is exposed through HTTP and rated medium severity due to its limited scope—only confidentiality is affected, with no impact to data integrity or system availability.

Source data · NVD / CISA · public domain

CVSS
3.1 · 5.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weaknesses (CWE)
CWE-200
Affected products
1 configuration(s)
Published / Modified
2026-06-17 / 2026-06-17

NVD description (verbatim)

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-46790 is an unauthenticated information disclosure flaw in Oracle WebCenter Content 14.1.2.0.0 classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The attack vector is network-based with low complexity, requires no privileges, and involves no user interaction. The CVSS 3.1 base score of 5.3 reflects the confidentiality impact within an unchanged scope boundary. The vulnerability permits unauthorized access to a subset of content repository data accessible via HTTP endpoints, though integrity and availability remain uncompromised.

Business impact

Unauthorized data access in WebCenter Content could expose sensitive business documents, customer information, or proprietary content stored in the repository. The blast radius is limited to readable data subsets, but organizations relying on WebCenter Content for document management or collaboration should assume that sensitive information may have been disclosed if the system remained unpatched during active exploitation. Reputational and compliance implications depend on the classification of exposed data under GDPR, HIPAA, or industry-specific regulations.

Affected systems

Oracle WebCenter Content version 14.1.2.0.0 is confirmed affected. Organizations should verify whether they are running this specific version or later versions to determine patch status. WebCenter Content is typically deployed in enterprise content management and Oracle Fusion Middleware environments. The scope is narrower than enterprise-wide vulnerability; exposure is limited to systems explicitly running the affected product and version.

Exploitability

The vulnerability is easily exploitable in practical terms: it requires only network access, no authentication, no user interaction, and low technical complexity. An attacker can trigger the flaw via standard HTTP requests without credentials, making reconnaissance and opportunistic exploitation feasible for unskilled attackers or automated scanning. The lack of complexity and authentication requirements significantly lowers the bar for abuse, though the impact remains confined to data confidentiality.

Remediation

Apply the appropriate security patch issued by Oracle for CVE-2026-46790—verify the exact patch version and bundle against Oracle's official security advisory and patch release notes. If patches are not immediately available, implement network-level access controls to restrict HTTP access to WebCenter Content to trusted internal networks or IP ranges, and monitor for suspicious read requests. Consider disabling or isolating the affected WebCenter Content instance if it is not mission-critical pending patch deployment.

Patch guidance

Consult Oracle's official security advisory and patch release notes for CVE-2026-46790 to identify the correct patch bundle and version for your WebCenter Content deployment. Patches are typically released as cumulative updates or critical patch updates (CPU). Test patches in a non-production environment before broad rollout to ensure compatibility with your Oracle Fusion Middleware configuration. Verify patch application by confirming the installed version matches the advisory guidance. If your organization uses Oracle support contracts, prioritize patch deployment in your standard maintenance windows.

Detection guidance

Monitor WebCenter Content HTTP access logs for unauthenticated read requests to sensitive content endpoints, particularly those returning data without authentication headers or session tokens. Network intrusion detection signatures for CVE-2026-46790 may be available through threat intelligence feeds; deploy them in your IDS/IPS if available. Conduct a data access audit on your WebCenter Content repository to identify what sensitive subsets may have been exposed and by whom, if logs support forensic review. Search for indicators of compromise or anomalous queries originating from external or untrusted IP addresses.

Why prioritize this

Although rated medium severity, this vulnerability merits prompt remediation because it requires no authentication and involves no user interaction—reducing operational friction for attackers. The network accessibility and ease of exploitation mean this flaw is attractive to both targeted and mass-scanning campaigns. The lack of integrity or availability impact means it may be overlooked, but data confidentiality breaches carry material business and regulatory risk. Organizations should prioritize patching according to their data sensitivity classification and exposure to external networks.

Risk score, explained

CVSS 3.1 score of 5.3 reflects the balance between high exploitability (unauthenticated network access, low complexity) and limited impact scope (confidentiality only, affecting a subset of accessible data). The lack of integrity, availability, or scope escalation prevents a higher rating. However, the practical risk to your organization depends on what data is stored in your WebCenter Content repository and whether the system is network-accessible; a data-sensitive deployment exposed to the internet carries greater residual risk than an internal-only instance.

Frequently asked questions

Does this vulnerability require authentication to exploit?

No. The vulnerability is exploitable by unauthenticated attackers with only network access via HTTP. No credentials, session tokens, or user interaction are required.

What data can be accessed through this vulnerability?

The vulnerability permits unauthorized read access to a subset of Oracle WebCenter Content accessible data. The exact scope depends on the repository configuration, content permissions, and what data is indexed or exposed through vulnerable endpoints. You should conduct a data audit to identify what sensitive information may be accessible.

Is this vulnerability included in Oracle's Known Exploited Vulnerabilities (KEV) catalog?

No. As of the publication date, CVE-2026-46790 is not listed in the CISA KEV catalog, meaning there is no confirmed evidence of active exploitation in the wild. However, the ease of exploitation and lack of authentication requirements mean active exploitation could emerge without warning.

What if we cannot patch immediately?

Implement network access controls to restrict HTTP connections to WebCenter Content from only trusted internal networks. Disable or isolate the system if not mission-critical. Monitor access logs closely for anomalous read requests. Coordinate with Oracle support on patch timelines and interim compensating controls.

This analysis is provided for informational purposes and reflects publicly available information as of the publication date. Organizations should verify all patch versions, affected product versions, and remediation steps against Oracle's official security advisories and their internal systems. The risk posed by this vulnerability varies based on your WebCenter Content deployment, data sensitivity, and network exposure; conduct your own risk assessment accordingly. Exploit code and detailed attack vectors are not provided. Consult your Oracle support contract or cybersecurity team for guidance specific to your environment. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).