CVE-2026-46780: Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core)
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
This is a high-severity vulnerability in the Core component of Oracle WebCenter Content: Imaging, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. An attacker with a low-privilege account can reach the vulnerable service over HTTP and exploit it without any victim interaction. Successful exploitation results in full takeover of the WebCenter Content: Imaging system, with complete loss of confidentiality, integrity, and availability. No fix version has been published by Oracle; HarborGuard is tracking the advisory for patch availability.
HarborGuard Coverage
Detection capability is available across every HarborGuard environment: the CVE is ingested from upstream Oracle and NVD advisory feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle affected WebCenter Content: Imaging components.
AvailableHarborGuard scores this CVE at CVSS 8.8 (HIGH) and is capable of weighting that score against each customer organization's compliance policy to determine breach of threshold and route findings to the appropriate team inbox automatically.
AvailableBecause Oracle has not published a fix version, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available the moment an upstream fix is released. For customers with auto-remediation enabled, the rebuild, regression test run, and PR against affected workloads will be triggered automatically at that point.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the WebCenter Content: Imaging service over the network via HTTP; local or physical access is not required but the service must be network-accessible.
- AuthenticationRequired
Any low-privilege account is sufficient; the attacker does not need administrative or elevated credentials, but some form of authenticated access is required.
- Victim interactionNot required
No user action or social engineering is needed; the attacker can exploit the vulnerability entirely on their own without involving another person.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and requires no special conditions, race conditions, or environment-specific factors to succeed.
Blast Radius
- A successful attacker reads all content and metadata stored in the WebCenter Content: Imaging repository, including documents, images, and associated records.
- A successful attacker modifies or deletes stored content, corrupts document workflows, and tampers with audit records held in the system.
- A successful attacker crashes or renders the WebCenter Content: Imaging service unavailable, disrupting any business processes that depend on it.
- Combined high impact across confidentiality, integrity, and availability constitutes a full system takeover as described in the CVE record.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-46780 is active and matched against customer images on every scan cycle. Because Oracle has not yet published a remediated version of WebCenter Content: Imaging, no patched rebuild is available at this time. HarborGuard monitors the Oracle and NVD advisory feeds on every ingest cycle and will make a patched-image rebuild available automatically once Oracle ships a fix. For customers with auto-remediation enabled, the rebuild, regression test, and PR flow will trigger without manual intervention at that point. In the interim, compensating controls worth considering include restricting HTTP access to the WebCenter Content: Imaging service via network policy to only known, trusted source addresses; placing the service behind an authenticated reverse proxy or API gateway to add a second authentication layer; and enabling egress filtering to limit what a compromised instance can reach inside the broader environment. These controls reduce exposure but do not eliminate the underlying vulnerability.
- Oracle Corporation / WebCenter Content: Imaging12.2.1.4.0 · 14.1.2.0.0
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H