CVE-2026-60472
Oracle · WebCenter Content: Imaging
A vulnerability in the Core component of Oracle WebCenter Content: Imaging allows low-privileged network attackers to potentially gain full control of the application.
Executive summary
A critical security flaw in Oracle WebCenter Content: Imaging allows authenticated attackers to compromise the system and achieve full takeover.
Vulnerability
This vulnerability affects the Core component of the application. It allows an attacker with low privileges and network access via HTTP to execute unauthorized actions, leading to a complete takeover of the product.
Business impact
While the CVSS score is 8.8, the potential for a complete system takeover makes this a high-priority risk. Successful exploitation could result in the compromise of sensitive imaging data, unauthorized administrative access, and significant operational disruption.
Remediation
Immediate Action: Apply the Oracle Critical Patch Update for July 2026 immediately to address this vulnerability.
Proactive Monitoring: Regularly review application access logs for anomalous behavior from low-privileged accounts that may indicate an attempt to escalate privileges or exploit core functionalities.
Compensating Controls: Implement strict network segmentation and ensure that access to the WebCenter Content: Imaging interface is restricted to authorized personnel via secure VPN or identity-aware proxy solutions.
Exploitation status
Public Exploit Available: No confirmed public exploit is available in our curated sources.
Analyst recommendation
Organizations utilizing Oracle WebCenter Content: Imaging must treat this vulnerability with high urgency. Applying the July 2026 Critical Patch Update is the only reliable method to mitigate the risk of a full system takeover by an authenticated attacker.