Unauthenticated Access Vulnerability in Oracle WebCenter Content by Oracle
CVE-2026-61295

7.1HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-61295?

A vulnerability in Oracle WebCenter Content allows an unauthenticated attacker with access to the infrastructure where the product operates to compromise its security. This flaw affects specific versions of the software and may lead to unauthorized access to critical data. Attackers exploiting this vulnerability could gain comprehensive access to all data managed by Oracle WebCenter Content, thus impacting not only this application but potentially also other products connected within the environment.

Affected Version(s)

Oracle WebCenter Content 12.2.1.4.0

Oracle WebCenter Content 14.1.2.0.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.