Junglewise Threat Intelligence

CVE-2026-60470: Oracle WebCenter Content: Imaging unauthorized data access in Core

CVE-2026-60470 · Severity: high · CVSS 8.7 · Published 2026-07-21

Technologies: Oracle WebCenter Content: Imaging. Vendors: Oracle.

Executive brief

Oracle WebCenter Content: Imaging, a tool used for managing and processing business documents, contains a high-severity security vulnerability. An attacker with basic user access can trick another person into performing an action that allows the attacker to view, modify, or delete sensitive business data. This could lead to a significant breach of confidential information or the unauthorized alteration of critical records across the system.

Technical details

A vulnerability in the Core component of Oracle WebCenter Content: Imaging (versions 12.2.1.4.0 and 14.1.2.0.0) allows for a scope-changing attack, likely a Cross-Site Scripting (XSS) or similar injection flaw. The vulnerability is easily exploitable by a low-privileged attacker with network access via HTTP, though it requires human interaction from a victim other than the attacker. Successful exploitation results in a 'Scope Change' (S:C), meaning the attacker can impact components beyond the immediate application, leading to total loss of confidentiality and integrity for all accessible data. No impact on availability was reported. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation.

Affected products

  • Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60470
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats