Executive brief
Oracle WebCenter Content: Imaging is a business application used for managing and processing large volumes of document images and metadata. A security vulnerability in this system allows an attacker with basic user credentials to gain full control over the application via the network. This could lead to the unauthorized access, modification, or deletion of sensitive corporate documents and a total disruption of imaging workflows.
Technical details
A vulnerability exists in the Core component of Oracle WebCenter Content: Imaging (part of Oracle Fusion Middleware). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. While the specific CWE is not detailed in the advisory, the impact is rated as high for confidentiality, integrity, and availability, potentially leading to a complete takeover of the affected component. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.