Junglewise Threat Intelligence

CVE-2026-60464: Oracle WebCenter Content: Imaging takeover via Core component

CVE-2026-60464 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle WebCenter Content: Imaging. Vendors: Oracle.

Executive brief

Oracle WebCenter Content: Imaging, a system used by businesses to manage and process digital document images, contains a high-severity security vulnerability. An attacker with basic user access to the corporate network can exploit this flaw to take full control of the imaging system. This could lead to the unauthorized viewing of sensitive documents, data deletion, or a total disruption of document processing workflows.

Technical details

A vulnerability exists in the Core component of Oracle WebCenter Content: Imaging (part of Oracle Fusion Middleware). The flaw is easily exploitable via the HTTP protocol and requires only low-privileged authentication. Successful exploitation allows an attacker to achieve a complete takeover of the affected instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats