CVE-2026-46805: Critical severity Oracle Oracle WebCenter Content vulnerability
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Restrict or disable direct public HTTP access to Oracle WebCenter Content. Allow access only from trusted IP ranges, over a VPN, or via an authenticated reverse proxy. Ensure sensitive operations require authenticated access.
Oracle WebCenter Content (Content Server) HTTP access exposure = restricted/disabled to public networks - Compensating control
Deploy network-level controls to limit exposure: enforce firewall/ACL rules to block unauthorized HTTP access to the Content Server, place the server in a segmented/protected network zone, and deploy a Web Application Firewall (WAF) to inspect and block malicious HTTP requests.
- Operational
Monitor and audit WebCenter Content logs for signs of unauthorized creation, deletion, or modification. Investigate suspicious activity and perform incident response if indicators are found. Apply vendor-supplied patches or updates as soon as they become available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46805?
The severity of CVE-2026-46805 is rated critical with a CVSS score of 9.3.
Who is affected by CVE-2026-46805?
CVE-2026-46805 affects the Oracle WebCenter Content product, specifically version 14.1.2.0.0.
How can I exploit CVE-2026-46805?
CVE-2026-46805 can be exploited by an unauthenticated attacker with network access via HTTP.
How do I fix CVE-2026-46805?
To fix CVE-2026-46805, it is recommended to update to a patched version of Oracle WebCenter Content provided by Oracle.
What are the potential impacts of CVE-2026-46805?
CVE-2026-46805 could allow an attacker to compromise Oracle WebCenter Content, leading to high confidentiality and integrity impacts.