Description
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker with network access can exploit a vulnerability in Oracle WebCenter Content: Imaging via the T3 and IIOP protocols to take over the application. The flaw, affecting the Core component, allows a remote attacker to execute code with the privileges of the application process, resulting in total compromise of confidentiality, integrity, and availability. The CVSS 3.1 score of 9.8 indicates a critical severity and reflects the full loss of control over the affected system.

Affected Systems

Oracle Corporation’s WebCenter Content: Imaging product is affected, specifically versions 12.2.1.4.0 and 14.1.2.0.0. These releases remain widely deployed in enterprise environments that rely on imaging capabilities within the Fusion Middleware stack.

Risk and Exploitability

The CVSS score of 9.8 assigns this vulnerability a critical rating. The EPSS score of less than 1% indicates that, despite its high severity, the likelihood of exploitation in the wild is currently low, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the attack vector is network‑based (AV:N), requires no prior authentication or user interaction, and can be performed by an attacker who can reach the T3 or IIOP interfaces over the network, making it potentially exploitable from publicly accessible services.

Generated by OpenCVE AI on August 2, 2026 at 22:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the Oracle WebCenter Content: Imaging patch or upgrade release announced in the Oracle July 2026 CPU advisory to eliminate the flaw.
  • Restrict inbound traffic to the T3 and IIOP ports (typically TCP 7001 for T3 and TCP 7002 for IIOP) using firewalls or network segmentation to limit the exposure surface until the patch is applied.
  • Configure the WebCenter Content: Imaging environment to allow only trusted IP ranges for T3/IIOP access, or disable these protocols if they are not required for business operations.

Generated by OpenCVE AI on August 2, 2026 at 22:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via T3/IIOP in Oracle WebCenter Content: Imaging

Thu, 30 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via T3/IIOP in Oracle WebCenter Content: Imaging

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via T3/IIOP in Oracle WebCenter Content: Imaging
Weaknesses CWE-284
CWE-798

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via T3/IIOP in Oracle WebCenter Content: Imaging
Weaknesses CWE-284
CWE-798

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content Imaging
CPEs cpe:2.3:a:oracle:webcenter_content__imaging:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content__imaging:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content Imaging
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content Imaging
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T18:12:21.826Z

Reserved: 2026-07-08T15:51:40.538Z

Link: CVE-2026-60463

cve-icon Vulnrichment

Updated: 2026-07-24T18:12:15.314Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function