Description
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability resides in the Core component of Oracle WebCenter Content: Imaging and permits an unauthenticated attacker with network access via HTTP to compromise the application. Successful exploitation requires a human interaction from a person other than the attacker; once achieved, the attacker can take over the entire WebCenter Content: Imaging environment. The CVSS 3.1 base score of 7.5 reflects that confidentiality, integrity and availability would all be substantially affected.

Affected Systems

Affected products are Oracle WebCenter Content: Imaging version 12.2.1.4.0 and 14.1.2.0.0. No other vendors or product variants are listed as impacted.

Risk and Exploitability

The CVSS score indicates high severity, but the EPSS probability is below 1 % and the vulnerability is not listed in the CISA KEV catalog, implying a relatively low likelihood of widespread exploitation at this time. The likely attack vector is via a public‑facing HTTP interface, where an attacker can initiate a request to the vulnerable Core component. Successful attacks would occur only when a legitimate user interacts with the system on behalf of the attacker, after which the attacker could gain full control of the application.

Generated by OpenCVE AI on August 4, 2026 at 17:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest Oracle security patch for WebCenter Content: Imaging that addresses CVE‑2026‑60467 for versions 12.2.1.4.0 and 14.1.2.0.0.
  • Restrict HTTP access to the WebCenter Content: Imaging server to trusted networks or enforce VPN usage, minimizing exposure to unauthenticated users.
  • If possible, disable or isolate the vulnerable Core component endpoint until a patch is applied.
  • Monitor application logs for unusual user sessions or activity that may indicate an exploitation attempt.

Generated by OpenCVE AI on August 4, 2026 at 17:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Full Takeover via HTTP Exploit Requiring Human Interaction in Oracle WebCenter Content: Imaging

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Full Takeover via HTTP Exploit Requiring Human Interaction in Oracle WebCenter Content: Imaging

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Exploitation Enabling Full WebCenter Content: Imaging Takeover
Weaknesses CWE-284

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Exploitation Enabling Full WebCenter Content: Imaging Takeover
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content Imaging
CPEs cpe:2.3:a:oracle:webcenter_content__imaging:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content__imaging:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content Imaging
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content Imaging
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:55:41.488Z

Reserved: 2026-07-08T15:51:40.538Z

Link: CVE-2026-60467

cve-icon Vulnrichment

Updated: 2026-07-24T18:02:54.216Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:15:03Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')