MEDIUM

CVE-2026-46790

Oracle Webcenter Content 2026-06-17 CVSS v3.1
CVSS
5.3

Description

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

Summary dbcve.org

A vulnerability in Oracle WebCenter Content's Content Server component (version 14.1.2.0.0) allows unauthenticated remote attackers to achieve unauthorized read access to a subset of accessible data via HTTP. The attack is easily exploitable over the network with no privileges required, targeting confidentiality through the CVSS vector indicating network exposure, low attack complexity, and no user interaction needed.

Mitigation

Apply the Oracle Critical Patch Update that addresses CVE-2026-46790, or obtain and deploy the specific patch for Oracle WebCenter Content 14.1.2.0.0. If patches are unavailable, restrict network access to the Content Server and implement additional access controls to limit exposure.

Weakness (CWE)

CWE-200 Information Exposure

EPSS Score

0.34%
Probability of exploitation in next 30 days
27.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE