Description
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all WebCenter Content: Imaging accessible data as well as unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An Oracle WebCenter Content: Imaging flaw in the Core component lets an attacker with low privileges and network access via HTTP exploit improper access control (CWE‑284). The vulnerability requires a separate, human‑initiated interaction but otherwise is easily exploitable. When successful, the attacker can create, delete, or modify critical data and gain unauthorized access to all data readable by the Imaging application, potentially affecting associated products through a scope change. The exploitation would compromise confidentiality and integrity of sensitive information.

Affected Systems

Oracle WebCenter Content: Imaging versions 12.2.1.4.0 and 14.1.2.0.0 are affected; the flaw impacts the core component of the product, and exploitation may propagate to other products that interact with Imaging.

Risk and Exploitability

The issue carries a CVSS 3.1 base score of 8.7, indicating high confidentiality and integrity impact. The EPSS score is below 1 %, suggesting that, so far, observed exploitation is rare. The flaw is not in the CISA KEV catalog, but the ability to be triggered over HTTP by a low‑privileged user and the requirement for a second party interaction still make it an appealing target for attackers. With a limited exploitation window yet significant damage potential, organizations should treat this as a high‑risk vulnerability.

Generated by OpenCVE AI on August 4, 2026 at 03:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade to a fixed version of WebCenter Content: Imaging.
  • Limit HTTP exposure of the Imaging component to trusted networks or a VPN and enforce strict role‑based permissions to reduce low‑privileged access.
  • Continuously monitor and log create, delete, modify actions on Imaging data, and investigate any anomalous activity promptly.

Generated by OpenCVE AI on August 4, 2026 at 03:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Enables Unauthorized Data Modification in Oracle WebCenter Content: Imaging

Thu, 30 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Enables Unauthorized Data Modification in Oracle WebCenter Content: Imaging

Tue, 28 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title WebCenter Content: Imaging Unauthorized Data Modification via HTTP
Weaknesses CWE-269

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title WebCenter Content: Imaging Unauthorized Data Modification via HTTP
Weaknesses CWE-269
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all WebCenter Content: Imaging accessible data as well as unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle webcenter Content Imaging
CPEs cpe:2.3:a:oracle:webcenter_content__imaging:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content__imaging:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content Imaging
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Webcenter Content Imaging
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:55:39.766Z

Reserved: 2026-07-08T15:51:40.539Z

Link: CVE-2026-60469

cve-icon Vulnrichment

Updated: 2026-07-24T17:33:00.916Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:00:03Z

Weaknesses