CVE-2026-46790
Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Summary dbcve.org
A vulnerability in Oracle WebCenter Content's Content Server component (version 14.1.2.0.0) allows unauthenticated remote attackers to achieve unauthorized read access to a subset of accessible data via HTTP. The attack is easily exploitable over the network with no privileges required, targeting confidentiality through the CVSS vector indicating network exposure, low attack complexity, and no user interaction needed.
Mitigation
Apply the Oracle Critical Patch Update that addresses CVE-2026-46790, or obtain and deploy the specific patch for Oracle WebCenter Content 14.1.2.0.0. If patches are unavailable, restrict network access to the Content Server and implement additional access controls to limit exposure.