Description
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A web-based vulnerability in Oracle WebCenter Content: Imaging allows a high‑privileged attacker who can reach the system over HTTP to exploit a flaw that is easily exploitable. Successful exploitation results in a complete takeover of the WebCenter Content: Imaging component, compromising confidentiality, integrity, and availability.

Affected Systems

Oracle WebCenter Content: Imaging versions 12.2.1.4.0 and 14.1.2.0.0 are impacted.

Risk and Exploitability

The CVSS score of 7.2 indicates high severity, while the EPSS score of < 1 % signals a low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Attackers need network access to the HTTP interface and the ability to authenticate with high privileges; the exploitation path is straightforward once connectivity is established.

Generated by OpenCVE AI on August 4, 2026 at 17:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch for WebCenter Content: Imaging referenced in the July 2026 CPU alert to these affected versions.
  • Restrict network access to the WebCenter Content: Imaging HTTP service, using firewall rules or network segmentation, until the patch is applied.
  • Enable detailed logging for WebCenter Content: Imaging and monitor for suspicious authentication or administrative activity.
  • Review Oracle’s security advisories for subsequent updates and verify that the fixed versions are deployed.

Generated by OpenCVE AI on August 4, 2026 at 17:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title WebCenter Content: Imaging HTTP Privilege Escalation Vulnerability

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title WebCenter Content: Imaging HTTP Privilege Escalation Vulnerability

Tue, 28 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title WebCenter Content: Imaging HTTP Privilege Escalation Leading to Full Compromise
Weaknesses CWE-862

Sat, 25 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title WebCenter Content: Imaging HTTP Privilege Escalation Leading to Full Compromise
Weaknesses CWE-284
CWE-862

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content Imaging
CPEs cpe:2.3:a:oracle:webcenter_content__imaging:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content__imaging:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content Imaging
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content Imaging
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:55:42.292Z

Reserved: 2026-07-08T15:51:40.538Z

Link: CVE-2026-60466

cve-icon Vulnrichment

Updated: 2026-07-24T17:50:43.775Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:15:03Z

Weaknesses