CVE-2026-46766: Critical severity Oracle Oracle WebCenter Content vulnerability
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the Oracle WebCenter Content HTTP interface to trusted IPs at the network perimeter (firewall/ACL) or place it behind a WAF to block exploit attempts from untrusted networks.
- Compensating control
Isolate affected Oracle WebCenter Content instances from untrusted networks (remove public HTTP access or move to a segmented network) until vendor fixes or mitigations are available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46766?
CVE-2026-46766 has a critical severity rating of 9.8.
How do I fix CVE-2026-46766?
To fix CVE-2026-46766, update to the latest patched version of Oracle WebCenter Content.
What products are affected by CVE-2026-46766?
CVE-2026-46766 affects the Oracle WebCenter Content product of Oracle Fusion Middleware versions 12.2.1.4.0 and 14.1.2.0.0.
What type of attackers can exploit CVE-2026-46766?
CVE-2026-46766 can be exploited easily by unauthenticated attackers with network access via HTTP.
What are the consequences of exploiting CVE-2026-46766?
Exploiting CVE-2026-46766 could lead to a complete compromise of the Oracle WebCenter Content server.