Junglewise Threat Intelligence

CVE-2026-60467: Oracle WebCenter Content: Imaging takeover via Core component

CVE-2026-60467 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Oracle WebCenter Content: Imaging. Vendors: Oracle.

Executive brief

Oracle WebCenter Content: Imaging, a tool used for managing and processing business documents and images, contains a security vulnerability that could allow an unauthorized person to take over the system. To succeed, an attacker must trick a legitimate user into performing a specific action, such as clicking a malicious link. If successful, this could lead to a total loss of confidentiality and control over the imaging platform and its stored data.

Technical details

This vulnerability exists in the Core component of Oracle WebCenter Content: Imaging (versions 12.2.1.4.0 and 14.1.2.0.0). It is classified as a high-severity issue that allows an unauthenticated attacker with network access via HTTP to compromise the application. The attack is considered difficult to exploit (Attack Complexity: High) and requires human interaction (User Interaction: Required) from a person other than the attacker. A successful exploit can result in a complete takeover of the WebCenter Content: Imaging instance, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60467

References

Related threats