Junglewise Threat Intelligence

CVE-2026-46780: Oracle WebCenter Content: Imaging auth bypass in Core component

CVE-2026-46780 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Oracle WebCenter Content: Imaging. Vendors: Oracle.

Executive brief

Oracle WebCenter Content: Imaging, a tool used by businesses to manage and process document images, contains a security vulnerability in its core component. An attacker with low-level user credentials can exploit this flaw over the network to gain full control of the imaging system. This could lead to the unauthorized access, modification, or deletion of sensitive business documents and a total disruption of document processing workflows.

Technical details

A vulnerability in the Core component of Oracle WebCenter Content: Imaging (part of Oracle Fusion Middleware) is classified as a missing authentication for a critical function (CWE-306). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to compromise the application, potentially leading to a complete takeover (impacting confidentiality, integrity, and availability). The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats