CVE-2026-46783: Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core)
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 9.8
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An unauthenticated remote compromise vulnerability affects Oracle WebCenter Content: Imaging (Core component) in versions 12.2.1.4.0 and 14.1.2.0.0. The flaw is reachable over HTTP from any network location and requires no credentials or user interaction to exploit. Successful exploitation gives an attacker full control of the affected system, including the ability to read, modify, or destroy data and disrupt service availability. No fix version has been published yet; HarborGuard is tracking the advisory and will make a patched-image rebuild available as soon as Oracle ships an upstream fix.
HarborGuard Coverage
Detection capability is available across every HarborGuard environment: CVE-2026-46783 is ingested from upstream advisory feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Oracle WebCenter Content: Imaging. Any image running an affected version (12.2.1.4.0 or 14.1.2.0.0) will surface in the findings queue automatically.
AvailableHarborGuard is capable of scoring this CVE at its published CVSS 3.1 rating of 9.8 (Critical) and weighting that score against each environment's compliance policy to determine priority and routing. Findings are routable to the appropriate team inbox inside each customer organization based on image ownership and policy configuration.
AvailableNo upstream fix version exists for CVE-2026-46783 at this time. HarborGuard re-evaluates the Oracle advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment Oracle publishes a remediated release; customers with auto-remediation enabled will receive a rebuilt image, a regression-test run, and a PR opened against affected workloads without manual intervention.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the WebCenter Content: Imaging service over the network via HTTP; there is no requirement for local or physical access.
- AuthenticationNot required
No credentials of any kind are needed; the attack is fully unauthenticated.
- Victim interactionNot required
No user or administrator action is required to trigger the vulnerability; the attacker operates entirely without victim involvement.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and imposes no special pre-conditions, race conditions, or environmental requirements on the attacker.
Blast Radius
- A successful attacker gains full read access to all content managed by WebCenter Content: Imaging, including stored documents, metadata, and any credentials or tokens held in the application.
- The attacker can modify or delete persisted documents, index records, and configuration data, corrupting the integrity of the content repository.
- The attacker can crash or render the WebCenter Content: Imaging service completely unavailable, disrupting any workflows or business processes that depend on it.
- Because the CVE description characterizes the outcome as full system takeover, the attacker also gains the ability to execute arbitrary operations under the identity of the application process, potentially pivoting to other systems on the same host or network segment.
How HarborGuard Handles This
Available on HarborGuard: CVE-2026-46783 carries a Critical CVSS score of 9.8 with no published fix, making it a high-priority advisory to monitor. Because no upstream patch exists, HarborGuard re-checks the Oracle advisory feed on every ingest cycle; the moment Oracle publishes a remediated version, a patched-image rebuild becomes available and, for customers with auto-remediation enabled, a rebuild, regression run, and PR against affected workloads will be triggered without manual steps. In the interim, compensating controls are strongly advised: apply strict network-policy rules to limit HTTP access to WebCenter Content: Imaging endpoints to known-good sources only; consider placing the service behind an API gateway or WAF configured to allowlist expected request patterns; and evaluate whether the imaging component can be isolated from broader internal network segments through egress filtering until Oracle ships a fix. HarborGuard will surface any policy-violating exposure automatically as findings continue to be evaluated against each environment's compliance configuration.
- Oracle Corporation / WebCenter Content: Imaging12.2.1.4.0 · 14.1.2.0.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H