PatchSiren cyber security CVE debrief
CVE-2026-60470 Oracle Corporation CVE debrief
A high-severity vulnerability was discovered in Oracle Fusion Middleware's WebCenter Content: Imaging, tracked as CVE-2026-60470, with a CVSS score of 8.7. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks require human interaction and can significantly impact additional products. The vulnerability can result in unauthorized creation, deletion, or modification access to critical data or all WebCenter Content: Imaging accessible data, as well as unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data.
- Vendor
- Oracle Corporation
- Product
- WebCenter Content: Imaging
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-25
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-25
Who should care
Organizations using Oracle Fusion Middleware's WebCenter Content: Imaging versions 12.2.1.4.0 and 14.1.2.0.0 should prioritize patching this vulnerability. Affected operators, platforms, vulnerability-management, and security teams should review the official advisory and plan vendor-supported updates or mitigations.
Technical summary
CVE-2026-60470 is a vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all WebCenter Content: Imaging accessible data as well as unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data.
Defensive priority
High
Recommended defensive actions
- Apply the patch as soon as possible
- Restrict network access to WebCenter Content: Imaging
- Monitor for suspicious activity
- Implement compensating controls
- Verify inventory and perform retesting
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-07-21T22:17:49.527Z and was last modified on 2026-07-25T05:16:39.067Z. The NVD entry is currently Undergoing Analysis. Oracle Fusion Middleware's WebCenter Content: Imaging is affected, with versions 12.2.1.4.0 and 14.1.2.0.0 vulnerable. Defenders should verify inventory, perform retesting, and monitor for suspicious activity.
Official resources
-
CVE-2026-60470 CVE record
CVE.org
-
CVE-2026-60470 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:49.527Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.