Junglewise Threat Intelligence

CVE-2026-60452: Oracle WebCenter Content: Imaging unauthorized data access in Core component

CVE-2026-60452 · Severity: high · CVSS 8.5 · Published 2026-07-21

Technologies: Oracle WebCenter Content: Imaging. Vendors: Oracle.

Executive brief

Oracle WebCenter Content: Imaging, a tool used for managing and processing document images within business workflows, contains a security vulnerability. An attacker with basic user credentials can exploit this over the network to gain unauthorized access to sensitive business data. This could result in the theft of critical information or the unauthorized modification and deletion of records, potentially impacting other integrated business systems.

Technical details

A vulnerability exists in the Core component of Oracle WebCenter Content: Imaging (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. The vulnerability is characterized by a scope change (Status: C), meaning an exploit can impact components beyond the immediate security scope of WebCenter Content: Imaging. Successful exploitation allows for unauthorized high-impact confidentiality breaches (access to all data) and low-impact integrity violations (unauthorized update/insert/delete). The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats