Description
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. While the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data as well as unauthorized update, insert or delete access to some of WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-07-21
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a low‑privileged attacker with HTTP network access to compromise Oracle WebCenter Content: Imaging. Successful exploitation gives the attacker unauthorized read access to critical data, and the ability to insert, update or delete accessible data. The CVSS 3.1 Base Score of 8.5 reflects high confidentiality impact and moderate integrity impact, and the scope change indicates that additional products may also be affected when the attack succeeds.

Affected Systems

Oracle WebCenter Content: Imaging, Fusion Middleware component Core, versions 12.2.1.4.0 and 14.1.2.0.0 are affected. Only these two releases are listed as vulnerable in the advisory.

Risk and Exploitability

The vulnerability is considered high severity but the EPSS score is below 1%, indicating a low likelihood of exploitation at present. The attack vector is network-based via HTTP, and the vulnerability requires a low privileged attacker. It is not listed in CISA’s KEV catalog, and the scope change raises the possibility that related applications might be affected once the vulnerability is leveraged.

Generated by OpenCVE AI on August 2, 2026 at 22:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle WebCenter Content: Imaging security patch released in the CPUJuly 2026 advisory to all affected 12.2.1.4.0 and 14.1.2.0.0 deployments.
  • If a patch cannot be applied immediately, restrict external HTTP access to the analyzed servers, lean on network segmentation and ensure only trusted IP addresses can reach the service.
  • Enable detailed logging and audit trails for data access operations to detect unauthorized reads or writes, and schedule regular log reviews.

Generated by OpenCVE AI on August 2, 2026 at 22:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low-Privileged HTTP Attack in Oracle WebCenter Content: Imaging

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Attack Exploits Unauthorized Access in Oracle WebCenter Content: Imaging

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Attack Exploits Unauthorized Access in Oracle WebCenter Content: Imaging

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. While the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data as well as unauthorized update, insert or delete access to some of WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle webcenter Content Imaging
CPEs cpe:2.3:a:oracle:webcenter_content__imaging:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content__imaging:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content Imaging
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Webcenter Content Imaging
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:27:20.197Z

Reserved: 2026-07-08T15:51:40.537Z

Link: CVE-2026-60452

cve-icon Vulnrichment

Updated: 2026-07-24T14:27:13.838Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:30:04Z

Weaknesses