Description
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all WebCenter Content: Imaging accessible data as well as unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged attacker with network connectivity can abuse an HTTP endpoint in Oracle WebCenter Content: Imaging to compromise the application. Successful exploitation permits the attacker to create, delete, or alter any data that the application can access, and may grant full read access to all such data. The vulnerability is a weakness in the core component, enabling the attacker to bypass normal security controls. The impact is classified as a high‑severity confidentiality and integrity breach per the CVSS 3.1 score of 8.7.

Affected Systems

Oracle WebCenter Content: Imaging versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability is present in the core component of the product and may also affect other Oracle Fusion Middleware components due to a scope change.

Risk and Exploitability

The CVSS base score indicates a high severity. The EPSS score is reported as less than 1%, suggesting that the likelihood of exploitation at this time is very low, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the attack requires only HTTP access and low privileges, but also human interaction from a non‑attacker to complete the compromise, which increases the friction for exploitation. The vulnerability can impact additional products because of a scope change, potentially expanding the damage footprint.

Generated by OpenCVE AI on August 4, 2026 at 17:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebCenter Content: Imaging patch or upgrade to a later release that addresses the vulnerability as described in the official Oracle CPU (July 2026) advisory.
  • If an immediate upgrade is not possible, restrict network access to the HTTP interfaces of WebCenter Content: Imaging and enforce strict authentication and authorization controls.
  • Regularly monitor application and network logs for anomalous activity and validate that no unauthorized data modifications occur.

Generated by OpenCVE AI on August 4, 2026 at 17:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enabling Unauthorized Data Modification in Oracle WebCenter Content: Imaging

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enabling Unauthorized Data Modification in Oracle WebCenter Content: Imaging

Tue, 28 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle WebCenter Content: Imaging
Weaknesses CWE-640

Sat, 25 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle WebCenter Content: Imaging
Weaknesses CWE-284
CWE-640

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all WebCenter Content: Imaging accessible data as well as unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle webcenter Content Imaging
CPEs cpe:2.3:a:oracle:webcenter_content__imaging:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content__imaging:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content Imaging
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Webcenter Content Imaging
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:55:38.994Z

Reserved: 2026-07-08T15:51:40.539Z

Link: CVE-2026-60470

cve-icon Vulnrichment

Updated: 2026-07-24T17:27:47.789Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:15:03Z

Weaknesses