CVE-2026-46789: Critical severity Oracle Oracle WebCenter Content vulnerability
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to Oracle WebCenter Content (version 14.1.2.0.0) HTTP endpoints to trusted IPs and internal networks using firewalls/ACLs; block or do not expose the service to the public Internet.
- Compensating control
Place a Web Application Firewall (WAF) or HTTP reverse proxy in front of Oracle WebCenter Content (version 14.1.2.0.0) to detect and block exploit attempts over HTTP.
- Operational
Assume possible compromise of Oracle WebCenter Content (version 14.1.2.0.0): perform incident response actions including isolating affected hosts, reviewing access and application logs for suspicious activity, and rotating any credentials, API keys, or secrets used by the application.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46789?
The severity of CVE-2026-46789 is critical, with a CVSS score of 9.6.
How do I fix CVE-2026-46789?
To fix CVE-2026-46789, you should apply the latest patches provided by Oracle for Oracle WebCenter Content.
Who is affected by CVE-2026-46789?
CVE-2026-46789 affects users of Oracle WebCenter Content version 14.1.2.0.0.
Can CVE-2026-46789 be exploited remotely?
Yes, CVE-2026-46789 can be exploited by an unauthenticated attacker with network access via HTTP.
What are the potential impacts of CVE-2026-46789?
CVE-2026-46789 can lead to complete compromise of Oracle WebCenter Content, resulting in unauthorized data access and disruption.