CVE-2026-61291: High severity Oracle Oracle WebCenter Content vulnerability
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle WebCenter Content executes to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs low-privileged access and a logon to the infrastructure where Oracle WebCenter Content is running. The CVSS vector identifies the attack vector as local and requires low privileges; no user interaction is required.
Which deployments are identified as affected?
The affected component is Oracle WebCenter Content Content Server in supported versions 12.2.1.4.0 and 14.1.2.0.0.
What is the potential impact of successful exploitation?
Successful exploitation can result in takeover of Oracle WebCenter Content, with high impacts to confidentiality, integrity, and availability.