CVE-2026-46780: Oracle WebCenter Content Imaging Privilege Escalation
A flaw in Oracle WebCenter Content: Imaging allows someone with a low-level user account to take complete control of the imaging system over the network. The vulnerability requires only basic network access and valid login credentials—no special interaction or social engineering is needed. Once exploited, an attacker gains full read, write, and administrative capabilities, effectively compromising the entire imaging application.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.8 HIGH · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-306
- Affected products
- 2 configuration(s)
- Published / Modified
- 2026-06-17 / 2026-06-18
NVD description (verbatim)
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-46780 is an authentication or authorization bypass vulnerability (CWE-306: Missing Authentication for Critical Function) in the Core component of Oracle WebCenter Content: Imaging. The flaw permits a low-privileged, authenticated user to escalate privileges and achieve complete system compromise via HTTP. The attack is straightforward (low attack complexity) and does not require user interaction or special network conditions. Affected versions are 12.2.1.4.0 and 14.1.2.0.0 of WebCenter Content: Imaging.
Business impact
Compromise of WebCenter Content: Imaging can result in unauthorized access to, modification of, or destruction of business-critical imaging documents and metadata. For organizations using WebCenter Content: Imaging as a document management or case imaging system, successful exploitation enables data theft, fraudulent document alteration, audit trail tampering, and operational disruption. The high CVSS score (8.8) reflects the severity: confidentiality, integrity, and availability impacts are all present, meaning an attacker can read sensitive documents, alter records, and render the imaging system unavailable.
Affected systems
Oracle WebCenter Content: Imaging versions 12.2.1.4.0 and 14.1.2.0.0 are confirmed vulnerable. Organizations running these versions in production, particularly those that expose the imaging system to internal networks or grant non-administrative user accounts, face direct risk. Verify your installed version against the product security advisory. Versions outside the stated ranges should be reviewed against Oracle's security guidance to confirm patching status.
Exploitability
The vulnerability is rated as easily exploitable because it requires only network access and a valid low-privilege user account—conditions commonly present in enterprise environments where multiple users need access to imaging systems. No zero-click or unauthenticated exploitation is possible, but the low barrier to entry (ordinary user credentials) and straightforward attack mechanism mean it could be weaponized quickly if details emerge. The flaw does not appear on the CISA KEV catalog as of this writing, but the severity and ease of exploitation suggest active monitoring is warranted.
Remediation
Prioritize patching affected versions. Contact Oracle or consult the security advisory for patch versions and installation procedures specific to your deployment. If immediate patching is not feasible, implement compensating controls: restrict HTTP network access to the imaging system via firewall rules, limit user account privileges to the minimum required by business function, enable detailed logging and alerting for imaging system access, and consider isolating the imaging environment pending patch deployment.
Patch guidance
Obtain the official patch from Oracle's security advisory for WebCenter Content: Imaging. The advisory will specify patch versions for 12.2.1.4.0 and 14.1.2.0.0. Apply patches in a test environment first, verify application functionality and any dependent processes, then roll out to production during a maintenance window. Document the patching date and version applied for compliance and audit records.
Detection guidance
Monitor for suspicious authentication and privilege escalation activity within WebCenter Content: Imaging. Flag unusual HTTP requests from low-privilege accounts attempting operations typically reserved for administrators. Review access logs for accounts performing bulk document retrieval, metadata modification, or system configuration changes outside their normal role. Set alerts for failed authentication attempts followed by successful privileged operations, which may indicate exploitation attempts. Correlate WebCenter Content: Imaging logs with identity and access management logs to detect anomalies.
Why prioritize this
This vulnerability scores HIGH (CVSS 8.8) due to complete system compromise potential combined with ease of exploitation. While authentication is required, valid user accounts are common in enterprise settings. The flaw affects core imaging functionality across multiple widely deployed versions. Rapid patching is justified to close the privilege escalation path before threat actors develop active exploits.
Risk score, explained
The CVSS 3.1 score of 8.8 reflects: (1) network accessibility with low attack complexity—standard HTTP requests suffice; (2) low privilege requirement—any authenticated user can initiate the attack; (3) no user interaction needed; (4) maximum impact across all three CIA triad components. The score aligns with the severity of allowing an ordinary user to fully compromise an imaging system that likely handles sensitive business documents.
Frequently asked questions
Do we need to patch immediately if WebCenter Content: Imaging is air-gapped or only accessible to trusted administrators?
Even in restricted deployments, prioritize patching within a defined maintenance window. An insider with a regular user account can still exploit the flaw. If the system is truly isolated and user access is heavily restricted, you have more time, but do not defer indefinitely; patches should be applied as part of normal change management.
What is CWE-306 and why does it matter for this vulnerability?
CWE-306 (Missing Authentication for Critical Function) indicates that the vulnerability stems from insufficient authentication or authorization checks on sensitive operations. In this case, the imaging system fails to properly validate that a low-privilege user should not be able to perform high-level administrative actions, allowing privilege escalation.
Is this vulnerability being actively exploited?
As of the published date, this CVE is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning no confirmed active exploitation in the wild has been reported to federal authorities. However, the ease of exploitation and high severity mean organizations should assume it will become a target and act accordingly.
Can we compensate for the vulnerability without patching right away?
Yes, if immediate patching is infeasible. Restrict network access to WebCenter Content: Imaging via firewall rules (allow only necessary IP ranges), enforce principle of least privilege for user accounts, enable verbose logging and alerting, and conduct periodic access reviews. These measures reduce but do not eliminate risk; patching remains the primary remediation.
This analysis is based on the CVE description and publicly available security data as of the publication date. Organizations are responsible for validating patch availability, compatibility, and deployment in their own environments. Consult Oracle's official security advisory for definitive patch guidance and supported upgrade paths. This page does not constitute legal or compliance advice. For regulatory requirements specific to your industry or jurisdiction, consult with compliance and legal teams. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-35265HIGHOracle Identity Manager Authentication Bypass – Critical Patch Required
- CVE-2026-35267HIGHOracle Identity Manager REST WebServices Authentication Bypass (CVSS 8.8)
- CVE-2026-35274HIGHOracle PeopleSoft PT PeopleTools Authentication Bypass
- CVE-2026-35276HIGHOracle PeopleSoft Authentication Bypass Vulnerability (8.1 CVSS)
- CVE-2026-35279HIGHPeopleSoft PT PeopleTools Authentication Bypass – Critical Patch Guidance
- CVE-2026-35289HIGHOracle PeopleSoft PT PeopleTools Authentication Bypass (CVSS 8.1)
- CVE-2026-35295HIGHOracle WebCenter Sites Authentication Bypass – High Risk Patch Alert
- CVE-2026-35299HIGHOracle WebLogic Server Console Authentication Bypass (CVSS 8.8)