Description
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE identifies a vulnerability in the Core component of Oracle WebCenter Content: Imaging. The weakness is an access control flaw (CWE-284), allowing a low‑privileged attacker who can reach the service over the network via the T3 or IIOP protocols to exploit the flaw, resulting in a full compromise of the application. This compromise jeopardizes the confidentiality, integrity, and availability of the system.

Affected Systems

Affected are Oracle Corporation's WebCenter Content: Imaging versions 12.2.1.4.0 and 14.1.2.0.0, as published in the Oracle Fusion Middleware portfolio. No other product versions are currently reported as vulnerable.

Risk and Exploitability

The CVSS score of 8.8 signals high severity. The EPSS score of less than 1% indicates a low probability of active exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only network access over T3 or IIOP and no special credentials; a low‑privileged attacker can send crafted requests to trigger the compromise once connectivity is established.

Generated by OpenCVE AI on August 4, 2026 at 03:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebCenter Content: Imaging patches released in the July 2026 CPU update.
  • Restrict inbound T3 and IIOP traffic to trusted hosts only, reducing exposure to potential attackers.
  • Monitor system logs for anomalous authentication attempts and unexpected service activity to detect and respond to exploitation attempts quickly.

Generated by OpenCVE AI on August 4, 2026 at 03:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Remote Compromise via T3/IIOP in Oracle WebCenter Content: Imaging

Tue, 28 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Exploit Enables Full Compromise of Oracle WebCenter Content: Imaging
Weaknesses CWE-286
CWE-693

Sat, 25 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Exploit Enables Full Compromise of Oracle WebCenter Content: Imaging
Weaknesses CWE-286
CWE-693

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content Imaging
CPEs cpe:2.3:a:oracle:webcenter_content__imaging:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content__imaging:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content Imaging
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content Imaging
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:55:43.092Z

Reserved: 2026-07-08T15:51:40.538Z

Link: CVE-2026-60465

cve-icon Vulnrichment

Updated: 2026-07-24T17:52:13.939Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:00:03Z

Weaknesses