Description
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via T3, IIOP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability enables an attacker who already has high network privileges to take full control of Oracle WebCenter Content Imaging by exploiting a flaw that becomes evident when the system communicates via the T3 or IIOP protocols. The weakness is classified as CWE-284, an improper privilege assignment, and it can lead to a complete loss of confidentiality, integrity, and availability of the application. The affected component is the Core part of the WebCenter Content Imaging product, with the CVSS 3.1 base score 7.2 indicating moderate to high severity.

Affected Systems

Affected are Oracle Corporation WebCenter Content Imaging, versions 12.2.1.4.0 and 14.1.2.0.0. These versions are supported by the latest CPU July 2026 advisory.

Risk and Exploitability

The flaw has a CVSS base score of 7.2, the EPSS score is less than 1% indicating a very low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote network-based exploitation through the T3 and IIOP protocols, requiring the attacker to already possess high privileged credentials in order to compromise the application.

Generated by OpenCVE AI on August 4, 2026 at 03:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in the CPU July 2026 advisory to fix the flaw.
  • Limit external access to the T3 and IIOP ports on the WebCenter Content Imaging server with firewall rules to reduce attack surface.
  • Enable detailed logging for authentication and connection attempts, and monitor for anomalies; if suspicious activity is detected, investigate and isolate the affected system as needed.

Generated by OpenCVE AI on August 4, 2026 at 03:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Remote Takeover Vulnerability in Oracle WebCenter Content Imaging via T3/IIOP

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Remote Takeover Vulnerability in Oracle WebCenter Content Imaging via T3/IIOP

Thu, 30 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title WebCenter Content: Imaging Remote Takeover via Network Access
Weaknesses CWE-269

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title WebCenter Content: Imaging Remote Takeover via Network Access
Weaknesses CWE-269
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via T3, IIOP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content Imaging
CPEs cpe:2.3:a:oracle:webcenter_content__imaging:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content__imaging:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content Imaging
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content Imaging
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:55:34.006Z

Reserved: 2026-07-08T15:51:40.541Z

Link: CVE-2026-60502

cve-icon Vulnrichment

Updated: 2026-07-24T15:41:11.966Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:45:03Z

Weaknesses