Executive brief
Oracle WebCenter Content: Imaging is a business tool used for managing and processing document images within an organization. A security vulnerability in this product allows an authorized user with low-level permissions to access or modify sensitive data they should not be able to see. This could lead to the exposure of confidential business records or unauthorized changes to document information.
Technical details
This vulnerability exists in the Core component of Oracle WebCenter Content: Imaging (part of Oracle Fusion Middleware). It is classified as an improper access control or similar flaw that allows a low-privileged attacker to perform unauthorized actions via HTTP. An attacker with a valid low-level account can exploit this over the network without user interaction to gain unauthorized access to critical data or perform unauthorized updates, insertions, or deletions of data. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published