CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-46785

Critical · CVSS 9.3

Oracle WebCenter Content — Cross-Site Request Forgery (CSRF)

CVSS
9.3
nvd
EPSS
KEV
No
Class
other
CWE-352

Description

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).

Search profile — drives PoC discovery

Symbols Content ServerIdcServiceWebCenter ContentCSRF tokenbinderIdcCommandRequestBinderHttpRequestHelperexecuteService
Keywords CVE-2026-46785Oracle WebCenter Content CSRFOracle Fusion Middleware CSRFWebCenter Content 14.1.2.0.0Content Server CSRFOracle WebCenter Content exploitCWE-352 Oracle WebCenter
Versions: 14.1.2.0.0

References

Status: enriched · ingested 2026-06-19T12:00:04.000Z · profiled 2026-06-19T12:30:04.000Z