Executive brief
Oracle WebCenter Content: Imaging is a business application used for managing and processing large volumes of document images and metadata. A security vulnerability in this product allows an attacker with basic user credentials to gain full control over the system via the network. This could lead to the unauthorized access, modification, or deletion of sensitive corporate documents and a total disruption of imaging workflows.
Technical details
A vulnerability exists in the Core component of Oracle WebCenter Content: Imaging (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is categorized as easily exploitable and requires only low-privileged authentication to execute. An attacker can exploit this over the network via HTTP without any user interaction. Successful exploitation results in a complete takeover of the affected component, impacting the confidentiality, integrity, and availability of the system (CVSS 8.8). Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle WebCenter Content: Imaging 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Published by Oracle in the July 2026 Critical Patch Update