CVE-2026-46795: Critical severity Oracle WebCenter Content vulnerability
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable or restrict direct HTTP listeners for the Content Server to internal networks or VPNs; if external access is required, enforce strict access controls and inspection through an approved gateway or WAF.
Oracle WebCenter Content (Content Server) HTTP access = disabled or restricted to internal/VPN - Compensating control
Restrict network access to Oracle WebCenter Content HTTP endpoints: block public internet access via firewall/ACLs and allow only trusted IP ranges, internal networks, or VPN connections to reach the service.
- Compensating control
Deploy a Web Application Firewall (WAF) or HTTP inspection rules in front of Oracle WebCenter Content to detect and block malicious HTTP requests targeting the application.
- Compensating control
Segment and isolate hosts running Oracle WebCenter Content from other critical systems and networks until a permanent fix is available to limit potential impact (network segmentation, VLANs, host isolation).
- Operational
Monitor and audit application and HTTP access logs for indicators of unauthorized creation, deletion, or modification. Investigate any suspicious activity and, if integrity loss is confirmed, restore affected content from known-good backups.
- Operational
If compromise is suspected, review and revoke or rotate credentials and service accounts that access Oracle WebCenter Content and review user permissions for unauthorized changes.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46795?
CVE-2026-46795 has a severity rating of critical with a CVSS score of 9.3.
How do I fix CVE-2026-46795?
To fix CVE-2026-46795, upgrade to the latest patched version of Oracle WebCenter Content.
What types of attacks can CVE-2026-46795 facilitate?
CVE-2026-46795 allows unauthenticated attackers to compromise Oracle WebCenter Content via network access.
Which version of Oracle WebCenter Content is affected by CVE-2026-46795?
The affected version of Oracle WebCenter Content is 14.1.2.0.0.
What component of Oracle Fusion Middleware is impacted by CVE-2026-46795?
CVE-2026-46795 impacts the Content Server component of Oracle WebCenter Content.