Junglewise Threat Intelligence

CVE-2026-46783: Oracle WebCenter Content: Imaging authentication bypass in Core component

CVE-2026-46783 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Oracle WebCenter Content: Imaging. Vendors: Oracle.

Executive brief

A critical vulnerability has been identified in Oracle's document imaging and management software. This flaw allows an unauthorized person to gain full control over the system remotely over the internet without needing a username or password. An attacker could steal sensitive business documents, alter records, or disrupt document processing operations entirely.

Technical details

This vulnerability is classified as a missing authentication for a critical function (CWE-306) within the Core component of Oracle WebCenter Content: Imaging. It is remotely exploitable via HTTP without any prior authentication or user interaction (AV:N/AC:L/PR:N/UI:N). An attacker can leverage this flaw to gain unauthorized access to the application, potentially leading to a full compromise of confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle June 2026 Critical Patch Update published

References

Related threats