Description
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the WebCenter Content: Imaging executes to compromise WebCenter Content: Imaging. While the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw, an instance of CWE‑284 Improper Access Control, resides in the Core component of Oracle WebCenter Content: Imaging and permits an attacker with physical communication segment access to compromise the system without authentication. Successful exploitation can lead to full takeover of WebCenter Content: Imaging, thereby affecting confidentiality, integrity, and availability of data and services. The vulnerability is located in WebCenter Content: Imaging, but attacks may also affect additional products due to a scope change.

Affected Systems

Oracle WebCenter Content: Imaging versions 12.2.1.4.0 and 14.1.2.0.0 are affected. Users of these versions should verify installation and patch status.

Risk and Exploitability

The CVSS v3.1 base score of 8.3 indicates high severity, while the EPSS score of less than 1% shows a low exploitation probability as of the current data. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an internal, unauthenticated connection to the physical network segment; the attacker does not need elevated privileges outside the communication channel. If exploited, an attacker can fully control the affected instance and potentially reach other applications due to the scope change.

Generated by OpenCVE AI on August 4, 2026 at 03:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for WebCenter Content: Imaging 12.2.1.4.0 and 14.1.2.0.0 as released by Oracle.
  • Limit network access to the physical communication segment by firewalls or VPNs so that only trusted hosts can reach the WebCenter Content: Imaging appliance.
  • If a patch is unavailable, isolate the appliance from the rest of the network and monitor for anomalous activity, ensuring that any potential compromise does not propagate to other systems.

Generated by OpenCVE AI on August 4, 2026 at 03:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Physical Network Access Enables Remote Compromise of WebCenter Content: Imaging

Tue, 28 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Physical Network Access Enables Remote Compromise of WebCenter Content: Imaging

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the WebCenter Content: Imaging executes to compromise WebCenter Content: Imaging. While the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content Imaging
CPEs cpe:2.3:a:oracle:webcenter_content__imaging:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content__imaging:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content Imaging
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content Imaging
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:55:35.708Z

Reserved: 2026-07-08T15:51:40.539Z

Link: CVE-2026-60471

cve-icon Vulnrichment

Updated: 2026-07-24T17:13:19.451Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:00:03Z

Weaknesses