Junglewise Threat Intelligence

CVE-2026-60469: Oracle WebCenter Content: Imaging unauthorized data access in Core component

CVE-2026-60469 · Severity: high · CVSS 8.7 · Published 2026-07-21

Technologies: Oracle WebCenter Content: Imaging. Vendors: Oracle.

Executive brief

Oracle WebCenter Content: Imaging, a tool used for managing and processing business documents, contains a security vulnerability that could allow an attacker to gain unauthorized access to sensitive data. By tricking a legitimate user into performing a specific action, a low-privileged attacker can modify or delete critical business information. This could lead to significant data loss or unauthorized disclosure of confidential corporate records.

Technical details

A vulnerability in the Core component of Oracle WebCenter Content: Imaging (versions 12.2.1.4.0 and 14.1.2.0.0) allows a low-privileged attacker with network access via HTTP to compromise the application. The vulnerability is characterized by a CVSS 3.1 score of 8.7, indicating a 'Scope Change' (S:C), which often suggests a Cross-Site Scripting (XSS) or similar injection flaw that can impact other components. Exploitation requires human interaction from a user other than the attacker. Successful exploitation can result in unauthorized creation, deletion, or modification of all accessible data, as well as complete unauthorized access to sensitive information within the system.

Affected products

  • Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update
  • 2026-07-21: advisory: NVD publication date

References

Related threats