HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-46777Published Modified CNA oracle

CVE-2026-46777: Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Metrics

CVSS v3.1
9.1
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An unauthenticated remote vulnerability affects Oracle WebCenter Content (Content Server component), versions 12.2.1.4.0 and 14.1.2.0.0. The flaw is reachable over HTTP from any network without credentials or user interaction, making it trivially exploitable at scale. Successful exploitation gives an attacker full read access to all content managed by the server and the ability to create, modify, or delete critical data. No fix version has been published by Oracle; HarborGuard tracks the advisory and will surface a patched rebuild the moment upstream ships one.

HarborGuard Coverage

Detection

Detection for CVE-2026-46777 is available across every HarborGuard environment, with CVE data ingested from upstream feeds within minutes of publication and matched against all images in customer registries and CI/CD pipelines, including custom-built images that package Oracle WebCenter Content. Any image running an affected version (12.2.1.4.0 or 14.1.2.0.0) is flagged automatically.

Available
Triage

HarborGuard can score this finding at its published CVSS 3.1 rating of 9.1 (Critical), apply per-environment compliance policy weighting to adjust priority, and route alerts to the appropriate team inbox within each customer organization. The Critical severity tier ensures the finding surfaces at the top of remediation queues for environments where that policy tier is configured.

Available
Patch

Because no upstream fix has been published for CVE-2026-46777, HarborGuard re-checks the Oracle advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment Oracle releases a corrected version. For customers who opt into auto-remediation, the rebuild, regression run, and PR against affected workloads will be initiated without manual intervention as soon as a fix version becomes available.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the Content Server over the network via HTTP; no local or physical access is required, and there is no network-segment restriction.

  • AuthenticationNot required

    No credentials or existing account are needed; the vulnerability is exploitable by any unauthenticated caller.

  • Victim interactionNot required

    No user action is needed on the target system; the attacker drives the exploit entirely without social engineering.

  • Attack complexityDetail

    Attack complexity is Low, meaning the exploit is reliable and imposes no special conditions, race requirements, or environmental dependencies.

Blast Radius

  • Reads all content assets, documents, and metadata stored in Oracle WebCenter Content, including items classified as critical data.
  • Creates new content records or uploads arbitrary files into the Content Server repository.
  • Modifies or deletes existing content, metadata, and access-control records across the entire repository.
  • Because availability impact is rated None, the service itself stays running, meaning a persistent attacker can continue data access and manipulation without triggering an outage-based alert.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-46777 is active for any customer image found to include Oracle WebCenter Content 12.2.1.4.0 or 14.1.2.0.0. Because Oracle has not yet published a remediated version, no patched-image rebuild is available at this time. HarborGuard re-evaluates the Oracle advisory on every ingest cycle and will make the rebuild available, and initiate the auto-remediation PR flow for eligible customers, the moment a fix version is published. In the interim, recommended compensating controls include isolating Content Server instances behind network policy rules that restrict inbound HTTP access to known internal IP ranges, applying egress filtering to limit lateral movement from a compromised instance, and auditing Content Server access logs for unexpected unauthenticated requests. Customers should review Oracle's official advisory channel for interim workarounds and patch availability.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Oracle WebCenter Content
    12.2.1.4.0 · 14.1.2.0.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
References