CVE-2026-46808: Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).
Metrics
- CVSS v3.1
- 8.7
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A cross-site scripting or request-forgery class vulnerability (scope-changing, network-reachable) affects the Content Server component of Oracle WebCenter Content version 14.1.2.0.0. A low-privileged attacker who can reach the service over HTTP and persuade a victim to interact with a crafted request can compromise content outside the directly targeted component, reading or modifying all data accessible to the Content Server. No fix version has been published by Oracle; HarborGuard is tracking the advisory and will flag a patched rebuild the moment upstream ships a correction.
HarborGuard Coverage
Detection of CVE-2026-46808 is available across every HarborGuard environment: the CVE is ingested from upstream feeds (NVD, Oracle CPU advisories, and vendor security feeds) within minutes of publication and matched against all customer images, including custom-built images that bundle Oracle WebCenter Content 14.1.2.0.0. No manual configuration is required for baseline detection to run.
AvailableTriage is available with a CVSS 3.1 base score of 8.7 (HIGH severity), surfaced alongside per-environment compliance policy weighting so that teams with stricter data-classification rules see it prioritized accordingly. Findings are routed to the inbox or ticketing integration configured for each customer organization, so the right team receives the alert without manual filtering.
AvailableBecause no upstream fix version has been published for this CVE, HarborGuard re-checks the Oracle advisory on every ingest cycle and will make a patched-image rebuild available the moment Oracle releases a corrected version. In the meantime, compensating controls (network-policy isolation, egress filtering, and HTTP proxy restrictions) can be applied and are surfaced as recommended actions within the HarborGuard console.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the Oracle WebCenter Content Server over the network via HTTP; no local or physical access is needed.
- AuthenticationRequired
A low-privilege account is sufficient; the attacker must be authenticated, but no administrative rights are required.
- Victim interactionRequired
A person other than the attacker must interact with a crafted request or link, making this a social-engineering-dependent attack.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and requires no special race conditions or environmental prerequisites beyond network access and victim interaction.
Blast Radius
- Reads all content and data accessible to the Oracle WebCenter Content Server, including documents, metadata, and stored credentials or tokens surfaced through the Content Server interface.
- Modifies, creates, or deletes critical data held within Oracle WebCenter Content, potentially corrupting document repositories or altering access control records.
- Because the CVSS scope is changed, impact can extend beyond the directly attacked Content Server component to other products or services that trust or consume its data.
How HarborGuard Handles This
Available on HarborGuard: images containing Oracle WebCenter Content 14.1.2.0.0 are automatically flagged against this CVE as part of every scan cycle, with no manual rule creation needed. Because Oracle has not yet published a fix version, HarborGuard monitors the upstream advisory on each ingest pass and will make a patched-image rebuild available immediately upon upstream publication; customers with auto-remediation enabled will receive a rebuilt image, a regression-test run, and a pull request opened against affected workloads without additional intervention. While no patch exists, the HarborGuard console surfaces compensating-control recommendations including HTTP-layer network policy restrictions to limit which principals can reach the Content Server, egress filtering to reduce the blast radius of a scope-change event, and feature-flag or reverse-proxy gating to restrict access to the affected component to only the user accounts that require it.
- Oracle Corporation / Oracle WebCenter Content14.1.2.0.0
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N