Junglewise Threat Intelligence

CVE-2026-60468: Oracle WebCenter Content: Imaging data breach in Core component

CVE-2026-60468 · Severity: high · CVSS 7.1 · Published 2026-07-21

Technologies: Oracle WebCenter Content: Imaging. Vendors: Oracle.

Executive brief

Oracle WebCenter Content: Imaging, a tool used for managing and processing business documents and images, contains a security vulnerability in its core component. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete sensitive business data. This could lead to a significant breach of confidential information or the corruption of important corporate records.

Technical details

A vulnerability exists in the Core component of Oracle WebCenter Content: Imaging (versions 12.2.1.4.0 and 14.1.2.0.0). This is an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation enables the attacker to achieve unauthorized 'read' access to all accessible data, as well as 'update, insert, or delete' access to a subset of the data. The vulnerability is tracked as part of the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats