CVE-2026-46804: Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).
Metrics
- CVSS v3.1
- 8.7
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
This is a cross-site scripting or similar scope-changing injection vulnerability in Oracle WebCenter Content (Content Server component, version 14.1.2.0.0). A low-privileged attacker who can reach the service over HTTP must trick another user into taking an action, at which point the attack breaks out of the originating product and affects additional systems. Successful exploitation gives the attacker full read access to critical content data and the ability to create, modify, or delete that same data. No fix version has been published by Oracle; HarborGuard is tracking the advisory and will make a patched-image rebuild available as soon as an upstream fix is released.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Oracle WebCenter Content 14.1.2.0.0. Any image carrying the affected component is flagged immediately on the next scan cycle.
AvailableHarborGuard scores this CVE at CVSS 8.7 (HIGH) and weights it further against each customer org's compliance policy to determine priority and routing. Triage findings are delivered to the inbox or ticketing integration configured for the relevant team within each customer environment.
AvailableBecause no upstream fix version has been published, HarborGuard re-evaluates the advisory on every ingest cycle and will make a patched-image rebuild available the moment Oracle ships a corrected package. For customers who opt into auto-remediation, the rebuild, regression run, and PR against affected workloads will trigger automatically without requiring manual intervention.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the Oracle WebCenter Content service over the network via HTTP; no local or physical access is needed.
- AuthenticationRequired
Any low-privilege account is sufficient; the attacker does not need administrative credentials, but must be a valid authenticated user.
- Victim interactionRequired
A separate user (other than the attacker) must perform an action such as clicking a crafted link or loading a malicious page, making this a social-engineering-dependent attack.
- Attack complexityDetail
Exploit conditions are straightforward and reliable; no race conditions, special memory layout, or environmental timing are required.
Blast Radius
- Reads all content and critical data accessible within Oracle WebCenter Content, including documents, records, and stored credentials or tokens surfaced by the application.
- Creates, modifies, or deletes critical content records and configuration data stored in Oracle WebCenter Content.
- The scope change (S:C) means impact extends beyond WebCenter Content itself; additional products or services that trust or consume data from the affected instance can also be compromised.
How HarborGuard Handles This
Available on HarborGuard: because Oracle has not yet published a fix version for CVE-2026-46804, HarborGuard continuously re-checks the advisory on every ingest cycle and will trigger a patched-image rebuild automatically the moment upstream packages are available. For customers who opt into auto-remediation, that rebuild will include a regression run and an automatically opened PR against affected workloads. In the interim, recommended compensating controls include restricting network-policy access to the Content Server component so that only authorized internal clients can reach it over HTTP, applying egress filtering to limit the blast radius of any scope change, and enforcing session-based access controls to reduce the pool of accounts that could be leveraged for the required low-privilege authentication step. Images containing Oracle WebCenter Content 14.1.2.0.0 are flagged in any HarborGuard-connected registry or pipeline as soon as a scan runs.
- Oracle Corporation / Oracle WebCenter Content14.1.2.0.0
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N