CVE-2026-46805: Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).
Metrics
- CVSS v3.1
- 9.3
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
This is a critical-severity unauthenticated attack against the Content Server component of Oracle WebCenter Content (version 14.1.2.0.0), reachable over the network via HTTP. The attack requires a victim to take some action (such as clicking a malicious link), but no credentials are needed from the attacker's side. Successful exploitation gives an attacker full read access to all content the server can reach and the ability to create, modify, or delete that same data, with a scope change meaning the impact can spill into other products beyond WebCenter Content itself. HarborGuard is tracking this advisory and will make a patched-image rebuild available the moment Oracle publishes a fix version.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream Oracle and NVD feeds within minutes of publication and matched against all customer images, including custom-built images layering Oracle WebCenter Content. Any image found running version 14.1.2.0.0 of the Content Server component is flagged immediately.
AvailableHarborGuard scores this finding at CVSS 9.3 (Critical) and weights it further against each customer environment's compliance policy, which can elevate or suppress routing priority based on asset classification. Triage alerts are routed to the inbox or ticketing integration configured by each customer organization.
AvailableBecause Oracle has not yet published a fix version, HarborGuard re-checks the advisory on every ingest cycle and will surface a patched-image rebuild automatically the moment an upstream fix is released. For customers who opt into auto-remediation, the rebuild, regression test run, and PR against affected workloads will be triggered without manual intervention once a fix version becomes available.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the Content Server over the network via HTTP; no local or physical access is needed (AV:N).
- AuthenticationNot required
No credentials of any privilege level are required; the attacker starts the attack as an anonymous network caller (PR:N).
- Victim interactionRequired
A person other than the attacker must take some action, such as clicking a crafted link or visiting a malicious page, for the attack to succeed (UI:R).
- Attack complexityDetail
Exploit conditions are straightforward and reliable, with no race conditions or special environmental setup required (AC:L).
Blast Radius
- A successful attacker reads all data accessible to the Content Server, including stored documents, metadata, and user records.
- The attacker can create, overwrite, or delete any content the server manages, corrupting document repositories and audit trails.
- Because the CVSS scope is changed (S:C), the attacker's reach extends beyond WebCenter Content itself and can affect other products or services sharing the same environment.
How HarborGuard Handles This
Available on HarborGuard: because Oracle has not yet released a patched version of WebCenter Content 14.1.2.0.0, every ingest cycle re-checks the Oracle CPU advisory feed so the rebuild will be queued automatically the moment a fix is published. In the interim, compensating controls available to HarborGuard customers include network-policy isolation that restricts inbound HTTP access to the Content Server to trusted source ranges only, egress filtering to limit lateral movement in the event of compromise, and policy rules that flag any deployment of the affected version for immediate human review. For customers who opt into auto-remediation, the patched rebuild, regression-test run, and PR against affected workloads will fire without manual steps as soon as an upstream fix version is ingested. Given the CVSS 9.3 Critical rating and the scope-change flag, customers running version 14.1.2.0.0 should treat network isolation as an urgent priority until a vendor patch is available.
- Oracle Corporation / Oracle WebCenter Content14.1.2.0.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N