CVE-2026-46808: Oracle WebCenter Content Improper Access Control (CVSS 8.7)
Oracle WebCenter Content version 14.1.2.0.0 contains a privilege-escalation vulnerability accessible over the network that allows attackers with low-level credentials to manipulate or steal sensitive data. The attack requires tricking another user into performing an action (such as clicking a link or opening a file), but once successful, an attacker can read, modify, or delete critical information stored in WebCenter Content or connected systems. The flaw affects authorization controls rather than availability, meaning systems remain operational but security is compromised.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.7 HIGH · CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
- Weaknesses (CWE)
- CWE-284
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-17 / 2026-06-23
NVD description (verbatim)
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-46808 is an improper access control vulnerability (CWE-284) in Oracle WebCenter Content that breaks the boundary between privileged operations. The vulnerability exists in the Content Server component and is exploitable via HTTP by authenticated users with low privileges. The attack requires user interaction (UI:R) from a different user, suggesting a cross-user attack pattern—possibly involving social engineering, stored cross-site scripting, or request forgery. The scope change indicator (S:C) means successful exploitation can affect Oracle Fusion Middleware components beyond WebCenter Content itself. CVSS 3.1 score of 8.7 reflects high confidentiality and integrity impacts with no availability impact, indicating data theft and modification are the primary concerns.
Business impact
An attacker exploiting this vulnerability could gain unauthorized access to business-critical content managed within WebCenter Content, including documents, records, and collaborative assets. This poses direct risk to data governance, compliance (especially for regulated industries), and intellectual property protection. The scope change means downstream Oracle Fusion Middleware applications relying on WebCenter Content may also be compromised, potentially affecting ERP, HCM, or supply chain visibility. Data manipulation or deletion could disrupt operational continuity and audit trails. Organizations without strong compensating controls face high exposure to insider threats or external actors leveraging compromised low-privilege accounts.
Affected systems
Oracle WebCenter Content version 14.1.2.0.0 is the confirmed affected release. Organizations running this version in production should assume direct exposure. Earlier or later versions have not been documented as vulnerable in the advisory, but verification against Oracle's official security bulletins is essential before assuming safety. Any deployment of 14.1.2.0.0—whether on-premises or cloud—requires immediate assessment. Interconnected systems consuming WebCenter Content data or relying on its access controls should also be evaluated for secondary impact.
Exploitability
Exploitation is considered straightforward (AC:L, Easily exploitable per advisory) once an attacker has low-level credentials and network access. However, the requirement for user interaction from a non-attacker (UI:R) raises the bar slightly—the attacker must socially engineer or trick a legitimate user into triggering the malicious action. This is not a wormable vulnerability; it requires multi-step compromise. The network-accessible attack vector means any user with valid credentials anywhere on the internet could attempt exploitation, and the low privilege requirement means compromised service accounts, contractors, or junior staff pose significant risk.
Remediation
Oracle should release a patched version addressing the improper access control flaw. Until a patch is available and tested in your environment, implement mitigations: restrict WebCenter Content network access to trusted IP ranges or VPNs, disable unnecessary user accounts, implement strict multi-factor authentication for WebCenter access, and monitor access logs for suspicious privilege escalation or bulk data operations. Consider temporarily disabling features that require cross-user interaction (e.g., shared workflows) if operationally feasible. Review low-privileged account activity and access patterns to detect potential exploitation early.
Patch guidance
Await an official patch release from Oracle. When released, test thoroughly in a staging environment before production deployment, as Oracle Fusion Middleware patches can have dependencies and require service restarts. Plan patching around maintenance windows. Do not delay; a CVSS 8.7 vulnerability with scope change warrants expedited testing. If Oracle provides a version number (e.g., 14.1.3.0.0), verify it against the official Oracle security advisory before deploying. Some organizations may need to coordinate patching across multiple environments or instances if WebCenter Content is part of a larger architecture.
Detection guidance
Monitor WebCenter Content access logs for unusual privilege escalation patterns—specifically, low-privileged users accessing or modifying administrative resources. Look for rapid data export, bulk deletions, or unauthorized modifications correlated with social engineering attempts (phishing, pretexting). Search for suspicious HTTP requests that cross user boundaries or invoke unexpected API calls. If available, enable WebCenter Content audit trails at the highest detail level and correlate with network access logs. Watch for failed authentication attempts followed by successful low-privilege logins, which may indicate account compromise. Intrusion detection systems should flag unusual cross-user data access flows.
Why prioritize this
This vulnerability merits priority patching due to its combination of ease of exploitation, direct data breach risk, and scope extending to other Fusion Middleware products. The CVSS 8.7 score places it in the HIGH severity band. While not currently listed on CISA's Known Exploited Vulnerabilities (KEV) catalog, the straightforward attack pattern and low barrier to exploitation increase the likelihood of weaponization. Any organization running WebCenter Content in a regulated industry (finance, healthcare, government) faces compounded risk and should prioritize immediately after a patch becomes available.
Risk score, explained
The CVSS 8.7 (HIGH) score reflects the combination of High confidentiality and High integrity impacts, offset slightly by a non-critical barrier (user interaction requirement) and limited availability impact. The network-accessible attack vector and low privilege requirement keep the score elevated despite the UI:R constraint. The scope change (S:C) is a significant aggravating factor, doubling the impact rating in CVSS 3.1 and signaling that downstream systems are at risk. The absence of an availability impact prevents a Critical score, but the dual threat to confidentiality and integrity places this firmly in the top tier of patches to deploy in a typical enterprise backlog.
Frequently asked questions
Can we safely delay patching this vulnerability if we restrict WebCenter Content to internal-only network access?
Partial mitigation, but not sufficient. The vulnerability requires low-privileged network access, not public internet access, so internal users and compromised service accounts remain a threat. Network segmentation helps but does not eliminate risk from insider threats, lateral movement after a breach, or supply chain compromise. Patching should not be deferred based on network isolation alone; use isolation as a compensating control while prioritizing patch deployment.
Does this vulnerability allow unauthenticated attackers to bypass login entirely?
No. The vulnerability explicitly requires 'low privileged attacker with network access,' meaning a valid account is mandatory. However, low-privileged accounts are common (service accounts, read-only roles, contractor access), so the credential barrier is not as high as for an admin-only vulnerability. Focus your risk assessment on the population of low-privileged users and the likelihood that their accounts could be compromised or misused.
If we are running WebCenter Content 14.1.1 or 14.1.3, are we affected?
Based on the advisory, only 14.1.2.0.0 is explicitly listed as affected. However, Oracle's bulletins sometimes indicate broader version ranges (e.g., '14.1.2.0.0 and earlier'). You must verify the exact affected version range against the official Oracle security advisory before assuming your version is safe. Version numbers are critical—do not rely on major version alone.
What is the difference between this vulnerability and a standard privilege escalation flaw?
This flaw combines privilege escalation with scope change, meaning the impact extends beyond WebCenter Content to other Fusion Middleware products. A traditional privilege escalation might allow an attacker to move from User A to User B within one system; this vulnerability breaks isolation and can affect downstream or adjacent systems. This makes it more damaging in an integrated Oracle environment and justifies the higher CVSS score.
This analysis is provided for informational purposes and reflects the advisory published as of the ground-truth date (2026-06-17, modified 2026-06-23). Patch availability, version numbers, and remediation guidance are subject to change pending official Oracle security bulletins. Organizations should verify all technical details, including affected version ranges and patch release schedules, directly with Oracle before taking any action. This explainer does not constitute security advice specific to your environment; conduct a formal risk assessment aligned with your incident response plan and compliance obligations. No exploit code or proof-of-concept details are provided; focus on detecting and remediating based on the technical indicators outlined above. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-35262HIGHOracle Data Integrator Authentication Bypass – Data Exposure Risk
- CVE-2026-35269HIGHOracle Identity Manager REST WebServices Authentication Bypass
- CVE-2026-35271HIGHOracle PeopleSoft WebLogic Unauthenticated Data Access Vulnerability (CVSS 8.7)
- CVE-2026-35275HIGHOracle VM VirtualBox Shared Folders Privilege Escalation Vulnerability (CVSS 7.5)
- CVE-2026-35277HIGHOracle REST Data Services Authorization Bypass
- CVE-2026-35311HIGHOracle WebLogic Server Remote Takeover via Low-Privilege Access Control Flaw
- CVE-2026-35314HIGHOracle Access Manager Authentication Bypass (CVSS 7.3)
- CVE-2026-35315HIGHOracle WebCenter Content Remote Takeover via Low-Privilege HTTP Access