Unauthenticated Access Vulnerability in Oracle WebCenter Content
CVE-2026-70858

7.1HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70858?

An unauthenticated access vulnerability exists in Oracle WebCenter Content within Oracle Fusion Middleware, specifically in the Content Server component. This weakness allows an attacker to exploit the system through HTTP, requiring human interaction from a third party for successful execution. The vulnerability poses significant risks, including unauthorized updates, inserts, and deletions of accessible data, unauthorized reads of sensitive information, and can lead to a partial denial of service (DoS) for the application. The implications extend beyond just Oracle WebCenter Content, as successful exploitation may affect a range of associated products.

Affected Version(s)

Oracle WebCenter Content 12.2.1.4.0

Oracle WebCenter Content 14.1.2.0.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.