ZeroHour

CVE-2026-83353

moderate

Local Privilege Escalation to Full Takeover in Oracle WebCenter Content Server

CVSS 3.1
7.8 high
EPSS
Published
()
Modified
AI analysis

Oracle WebCenter Content (Fusion Middleware), specifically the Content Server component, contains an easily exploitable flaw in versions 12.2.1.4.0 and 14.1.2.0.0 that allows a low-privileged attacker who can log on to the host where the product runs to escalate privileges and compromise the entire WebCenter Content installation. Successful exploitation can result in complete takeover of the product, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8). Because the attack vector is local, the attacker must first have an account on or access to the underlying server infrastructure, which limits exposure to insiders, compromised credentials, or attackers who have already gained a foothold on the host. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof of concept is known, indicating no observed in-the-wild exploitation to date.

What to do: Apply the Oracle Critical Patch Update that addresses this issue to WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 as soon as it is available via My Oracle Support. Restrict and audit local OS-level accounts on servers hosting Content Server, enforce least privilege, and remove unnecessary interactive logon rights. Watch for anomalous privilege escalation or service-account activity on those hosts, since the flaw requires an existing foothold on the machine.

Affected
Oracle WebCenter Content (Fusion Middleware, Content Server component)12.2.1.4.0, 14.1.2.0.0
Estimated exposure
moderate≈ low thousands of enterprise installations worldwide (estimate) — Oracle WebCenter Content is an on-premises enterprise content management product typically deployed by mid-to-large organizations, and Oracle does not publish install counts; the local attack vector further limits the practically reachable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle WebCenter Content executes to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.