CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-46805

Critical · CVSS 9.3

Oracle WebCenter Content — Improper Access Control (CWE-284) — unauthenticated HTTP access allowing unauthorized read/write to critical data with scope change

CVSS
9.3
nvd
EPSS
KEV
No
Class
other
CWE-284

Description

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).

Search profile — drives PoC discovery

Symbols Content ServerWebCenter ContentOracle Fusion Middleware14.1.2.0.0cspujun2026
Keywords CVE-2026-46805Oracle WebCenter ContentContent ServerunauthenticatedCWE-284improper access controlFusion Middleware14.1.2.0.0PoCexploitscope changeunauthorized access
Versions: 14.1.2.0.0

References

Status: enriched · ingested 2026-06-19T12:00:04.000Z · profiled 2026-06-19T12:30:04.000Z