Junglewise Threat Intelligence

CVE-2026-46784: Oracle WebCenter Content: Imaging access control bypass in Core component

CVE-2026-46784 · Severity: critical · CVSS 9.1 · Published 2026-06-17

Technologies: Oracle WebCenter Content: Imaging. Vendors: Oracle.

Executive brief

Oracle WebCenter Content: Imaging is a business tool used for managing and processing document images within an organization. A critical security flaw allows an unauthorized person to access the system over the internet without a password. If exploited, an attacker could view, change, or delete sensitive corporate data, potentially leading to significant data loss or a breach of confidential information.

Technical details

A vulnerability classified as Improper Access Control (CWE-284) exists in the Core component of Oracle WebCenter Content: Imaging. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows the attacker to bypass security restrictions to perform unauthorized creation, deletion, or modification of all data accessible to the application. It also grants complete unauthorized access to all critical data within the system. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. Users are advised to consult the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle published security alert cspujun2026.html

References

Related threats