A critical CVSS 9.8 flaw in Oracle Fusion Middleware's WebCenter Content: Imaging lets an unauthenticated attacker fully compromise the product over the network via T3 or IIOP.
What Is It
CVE-2026-60463 is a critical vulnerability in the Core component of Oracle WebCenter Content: Imaging, part of Oracle Fusion Middleware. It carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The flaw is easily exploitable and allows an unauthenticated attacker with network access via the T3 or IIOP protocols to compromise the product. Successful exploitation results in a complete takeover of WebCenter Content: Imaging.
Why It Matters
The vulnerability requires no authentication, no user interaction, and low attack complexity, meaning any attacker who can reach the T3 or IIOP interfaces over the network can exploit it. With high impacts to confidentiality, integrity, and availability, a successful attack yields full takeover of the affected system. This combination, network-reachable, unauthenticated, and full-impact, places it among the most severe classes of enterprise middleware exposures.
What's Vulnerable
The affected product is Oracle WebCenter Content: Imaging (component: Core). The supported versions confirmed affected are:
- 12.2.1.4.0
- 14.1.2.0.0
Patch Status
Oracle addressed this vulnerability in its Critical Patch Update of July 2026. Administrators should apply the fixes described in the Oracle Critical Patch Update Advisory for July 2026. There is no CISA KEV entry for this CVE in the supplied source material, so active exploitation is not confirmed by KEV at this time.
Sources
- Oracle Critical Patch Update Advisory - July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60463, https://nvd.nist.gov/vuln/detail/CVE-2026-60463