Executive brief
A critical vulnerability exists in Oracle WebCenter Content: Imaging, a system used by organizations to manage and process document images. An unauthorized person can remotely take full control of the system over the network without needing a username or password. This could lead to the total loss of sensitive document data, unauthorized modification of records, and complete service disruption.
Technical details
A vulnerability in the Core component of Oracle WebCenter Content: Imaging (part of Oracle Fusion Middleware) allows for complete system takeover. The flaw is easily exploitable by an unauthenticated attacker with network access via the T3 or IIOP protocols. Successful exploitation grants the attacker full control over the Confidentiality, Integrity, and Availability of the affected service. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Published in Oracle Critical Patch Update July 2026