PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60470 Oracle Corporation CVE debrief

A high-severity vulnerability was discovered in Oracle Fusion Middleware's WebCenter Content: Imaging, tracked as CVE-2026-60470, with a CVSS score of 8.7. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks require human interaction and can significantly impact additional products. The vulnerability can result in unauthorized creation, deletion, or modification access to critical data or all WebCenter Content: Imaging accessible data, as well as unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data.

Vendor
Oracle Corporation
Product
WebCenter Content: Imaging
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-25
Advisory published
2026-07-21
Advisory updated
2026-07-25

Who should care

Organizations using Oracle Fusion Middleware's WebCenter Content: Imaging versions 12.2.1.4.0 and 14.1.2.0.0 should prioritize patching this vulnerability. Affected operators, platforms, vulnerability-management, and security teams should review the official advisory and plan vendor-supported updates or mitigations.

Technical summary

CVE-2026-60470 is a vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in WebCenter Content: Imaging, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all WebCenter Content: Imaging accessible data as well as unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data.

Defensive priority

High

Recommended defensive actions

  • Apply the patch as soon as possible
  • Restrict network access to WebCenter Content: Imaging
  • Monitor for suspicious activity
  • Implement compensating controls
  • Verify inventory and perform retesting
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-07-21T22:17:49.527Z and was last modified on 2026-07-25T05:16:39.067Z. The NVD entry is currently Undergoing Analysis. Oracle Fusion Middleware's WebCenter Content: Imaging is affected, with versions 12.2.1.4.0 and 14.1.2.0.0 vulnerable. Defenders should verify inventory, perform retesting, and monitor for suspicious activity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:49.527Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.