CVE-2026-46791: Oracle WebCenter Content Unauthenticated Data Access Vulnerability
An Oracle WebCenter Content vulnerability allows unauthenticated attackers to read sensitive data over the network without authentication. The flaw resides in the Content Server component of Oracle Fusion Middleware version 14.1.2.0.0. An attacker with network access can exploit this over HTTP to gain unauthorized access to critical information stored within WebCenter Content. The vulnerability does not allow attackers to modify or delete data, only to read it.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Weaknesses (CWE)
- CWE-284
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-17 / 2026-06-17
NVD description (verbatim)
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-46791 is an improper access control vulnerability (CWE-284) in Oracle WebCenter Content's Content Server component. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) indicates network-accessible exploitation with low attack complexity, no authentication requirement, and no user interaction needed. The high confidentiality impact reflects full access to WebCenter Content accessible data, while integrity and availability remain unaffected. The vulnerability requires only HTTP network access to trigger.
Business impact
Organizations running WebCenter Content 14.1.2.0.0 face immediate exposure of sensitive documents, records, and metadata stored within the content management system. This includes potential disclosure of confidential business documents, contracts, customer data, or compliance-sensitive information depending on what the organization stores. The lack of authentication requirement means the attack surface extends to any network-connected instance without additional defensive measures. Regulatory exposure may arise if personal or regulated data is compromised, and reputational damage could follow public disclosure.
Affected systems
Oracle WebCenter Content version 14.1.2.0.0 is affected. This is a specific point release of Oracle Fusion Middleware's content management component. Organizations should verify their WebCenter Content deployment version against this specific build number. Older and newer versions may or may not be affected—consult Oracle's security advisory for the complete affected version list and patched releases.
Exploitability
This vulnerability is easily exploitable. An unauthenticated attacker requires only network access and HTTP connectivity to trigger the flaw. No authentication, authentication bypass, or user interaction is required. The attack complexity is low, meaning no special conditions or timing dependencies exist. The simplicity of exploitation and absence of authentication barriers make this a high-priority concern for externally facing or less-restricted deployments.
Remediation
Apply the security patch released by Oracle for WebCenter Content. Verify the patched version number against Oracle's June 2026 Critical Patch Update advisory. As an interim measure, restrict HTTP network access to WebCenter Content instances through firewall rules, network segmentation, or access control lists to limit exposure to trusted networks only. Consider disabling or isolating affected instances pending patch deployment if they contain highly sensitive data.
Patch guidance
Oracle released a security patch coinciding with the vulnerability publication on June 17, 2026. Check Oracle's Critical Patch Update advisory for the specific patched version applicable to your deployment. Prioritize patching production instances immediately given the ease of exploitation and confidentiality impact. Test patches in a non-production environment first to ensure compatibility with your WebCenter Content configuration and dependent applications. Plan downtime accordingly, as patching may require a service restart.
Detection guidance
Monitor HTTP access logs for unusual or unauthorized requests to WebCenter Content endpoints. Look for patterns consistent with reconnaissance or data exfiltration, such as bulk requests for document metadata or repeated access to resources by unauthenticated sessions. Implement network detection rules for known attack signatures once available. Review WebCenter Content access logs for anomalous data access by accounts or sessions that should not have permissions. Consider enabling verbose logging on the Content Server component to capture failed authentication attempts or privilege escalation behaviors.
Why prioritize this
This vulnerability earns high priority due to the combination of easy exploitability (no authentication), high confidentiality impact (full data access), and network accessibility. The absence of authentication barriers and low attack complexity mean threat actors can weaponize this quickly and at scale. Any organization with internet-accessible WebCenter Content faces active risk. The June 2026 publication date suggests this is a recently disclosed flaw with limited historical attack data, but the attack profile indicates rapid exploitation is likely.
Risk score, explained
The CVSS 3.1 score of 7.5 (HIGH) reflects a vulnerability that is easily exploitable over the network by unauthenticated attackers with no user interaction required. The score is driven primarily by the high confidentiality impact, meaning complete access to sensitive data is possible. The lack of integrity or availability impact prevents a critical rating, but the data disclosure risk remains severe. Organizations storing highly sensitive information in WebCenter Content should treat this as critical regardless of the CVSS numeric score.
Frequently asked questions
Does this vulnerability allow attackers to modify or delete data?
No. The vulnerability results in unauthorized read access only (high confidentiality impact). Attackers cannot modify, delete, or corrupt data within WebCenter Content. However, the ability to read sensitive information is a serious breach that may violate privacy regulations or expose trade secrets.
Can this be exploited if WebCenter Content is behind a firewall?
Not directly over the network. If WebCenter Content is restricted to internal networks or behind a properly configured firewall that blocks inbound HTTP access, network-based exploitation from the internet is prevented. However, insider threats or compromised internal systems could still exploit the vulnerability internally.
Do older or newer versions of Oracle WebCenter Content have the same flaw?
Version 14.1.2.0.0 is confirmed affected. Oracle's advisory will specify all affected versions and the patched releases available for each. Do not assume other versions are vulnerable or safe without verification against the official advisory. Some versions may be out of support and unavailable for patching.
What should we do if we cannot patch immediately?
Implement network access controls to restrict HTTP connectivity to WebCenter Content to trusted internal networks only. Disable external access temporarily if the system is not critical for immediate business operations. Monitor access logs closely for suspicious activity. Increase audit logging and consider isolating the affected instance pending patch availability.
This analysis is based on the CVE disclosure as published on June 17, 2026. Patch version numbers and specific remediation steps should be verified against Oracle's official Critical Patch Update advisory. This vulnerability assessment does not constitute legal or compliance advice; organizations should consult their legal and compliance teams regarding regulatory implications. Exploit code and weaponized proof-of-concept details are not disclosed herein. This material is provided for informational purposes to support security decision-making only. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-35262HIGHOracle Data Integrator Authentication Bypass – Data Exposure Risk
- CVE-2026-35269HIGHOracle Identity Manager REST WebServices Authentication Bypass
- CVE-2026-35271HIGHOracle PeopleSoft WebLogic Unauthenticated Data Access Vulnerability (CVSS 8.7)
- CVE-2026-35275HIGHOracle VM VirtualBox Shared Folders Privilege Escalation Vulnerability (CVSS 7.5)
- CVE-2026-35277HIGHOracle REST Data Services Authorization Bypass
- CVE-2026-35311HIGHOracle WebLogic Server Remote Takeover via Low-Privilege Access Control Flaw
- CVE-2026-35314HIGHOracle Access Manager Authentication Bypass (CVSS 7.3)
- CVE-2026-35315HIGHOracle WebCenter Content Remote Takeover via Low-Privilege HTTP Access