Junglewise Threat Intelligence

CVE-2026-60471: Oracle WebCenter Content: Imaging takeover via Core component

CVE-2026-60471 · Severity: high · CVSS 8.3 · Published 2026-07-21

Technologies: Oracle WebCenter Content: Imaging. Vendors: Oracle.

Executive brief

Oracle WebCenter Content: Imaging, a tool used for managing and processing business documents, contains a high-severity vulnerability in its core component. An attacker with access to the same local network segment as the server could potentially take full control of the application. This could lead to the theft of sensitive business documents, unauthorized modification of records, or a complete shutdown of imaging services.

Technical details

A vulnerability exists in the Core component of Oracle WebCenter Content: Imaging (part of Oracle Fusion Middleware). The flaw is characterized by a CVSS 3.1 score of 8.3, with a scope change (S:C) indicating that a successful exploit can impact products beyond the immediate component. The attack vector is 'Adjacent', meaning the attacker must be on the same physical or logical network segment (e.g., local subnet, Bluetooth range) as the target. While the attack complexity is rated as high, a successful unauthenticated exploit results in a total loss of confidentiality, integrity, and availability (C:H/I:H/A:H), effectively allowing a full system takeover. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: advisory: Initial publication by Oracle and NVD

References

Related threats