Executive brief
Oracle WebCenter Content: Imaging, a business tool used for managing and processing document images, contains a security vulnerability in its core component. An attacker with high-level administrative privileges can exploit this flaw over the network to gain full control of the application. This could lead to the unauthorized access, modification, or deletion of sensitive business documents and a total disruption of imaging services.
Technical details
A vulnerability exists in the Core component of Oracle WebCenter Content: Imaging (part of Oracle Fusion Middleware). The flaw is easily exploitable by a high-privileged attacker with network access via HTTP. While the specific vulnerability class (e.g., injection, insecure deserialization) is not explicitly detailed in the advisory, the impact is a complete compromise of Confidentiality, Integrity, and Availability (CIA triad), effectively allowing a full system takeover. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date