Junglewise Threat Intelligence

CVE-2026-60502: Oracle WebCenter Content: Imaging takeover via Core component

CVE-2026-60502 · Severity: high · CVSS 7.2 · Published 2026-07-21

Technologies: Oracle WebCenter Content: Imaging. Vendors: Oracle.

Executive brief

Oracle WebCenter Content: Imaging is a business application used for managing and processing large volumes of document images and metadata. A security vulnerability in this product allows a high-privileged user to take full control of the system over the network. This could lead to the unauthorized access, modification, or deletion of sensitive corporate documents and a total disruption of imaging workflows.

Technical details

A vulnerability exists in the Core component of Oracle WebCenter Content: Imaging (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is exploitable by a high-privileged attacker via the T3 or IIOP protocols over a network. While the specific vulnerability class (e.g., deserialization) is not explicitly named in the advisory, the attack vector and the resulting 'takeover' impact are consistent with remote code execution or unauthorized administrative access. Successful exploitation grants the attacker full control over the Confidentiality, Integrity, and Availability of the affected component. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats