Description
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Core component of Oracle WebCenter Content: Imaging. It is an improper access control flaw (CWE‑284) that enables a low‑privileged attacker who can reach the application over HTTP to compromise the instance. Successful exploitation can lead to a complete takeover of the WebCenter Content: Imaging application, resulting in loss of confidentiality, integrity, and availability of data and services that the application manages.

Affected Systems

Affected deployments are Oracle WebCenter Content: Imaging version 12.2.1.4.0 and 14.1.2.0.0, the two releases listed by Oracle in the CPU update. No other versions are flagged as vulnerable in the public advisory.

Risk and Exploitability

The base CVSS 3.1 score of 8.8 indicates high severity, and the vector shows network access with low authentication and no user interaction. The EPSS score is less than 1%, and the vulnerability is not yet listed in the CISA KEV catalog. This indicates that while the technical risk is high, active exploitation in the wild is currently rare, yet any environment exposing the application over the network remains at significant risk.

Generated by OpenCVE AI on August 4, 2026 at 03:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU patch for WebCenter Content: Imaging 12.2.1.4.0 and 14.1.2.0.0 from the July 2026 update.
  • Limit exposure of WebCenter Content: Imaging by configuring firewall rules or a reverse‑proxy to restrict HTTP access to trusted networks or IP ranges.
  • Verify that authentication and authorization controls are correctly configured and that privileged accounts are monitored; update any custom access control lists if required.

Generated by OpenCVE AI on August 4, 2026 at 03:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Leading to Takeover of Oracle WebCenter Content: Imaging

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Leading to Takeover of Oracle WebCenter Content: Imaging

Tue, 28 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle WebCenter Content: Imaging via HTTP

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle WebCenter Content: Imaging via HTTP
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content Imaging
CPEs cpe:2.3:a:oracle:webcenter_content__imaging:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content__imaging:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content Imaging
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content Imaging
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:55:33.186Z

Reserved: 2026-07-08T15:51:40.541Z

Link: CVE-2026-60503

cve-icon Vulnrichment

Updated: 2026-07-24T15:40:32.260Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:45:03Z

Weaknesses