Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Client Bundle component of Oracle WebCenter Enterprise Capture and represents a CWE-306 Improper Authentication flaw. An unauthenticated attacker possessing network access to the T3 or IIOP ports can exploit the flaw, enabling full takeover of the application. Successful exploitation results in complete loss of confidentiality, integrity, and availability, reflected in a CVSS 3.1 base score of 9.8.

Affected Systems

Oracle WebCenter Enterprise Capture, versions 12.2.1.4.0 and 14.1.2.0.0, are part of Oracle Fusion Middleware and are widely deployed in enterprise environments. These two releases are the only ones known to be vulnerable; later revisions are considered fixed.

Risk and Exploitability

The CVSS score of 9.8 ranks this as critical, while the EPSS score of <1% indicates a low probability that the vulnerability will be actively exploited at any time. The flaw is not yet listed in CISA's KEV catalog, but the ability to compromise the system without authentication makes it a high priority target for defensive measures.

Generated by OpenCVE AI on August 4, 2026 at 17:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for WebCenter Enterprise Capture that resolves the remote takeover vulnerability, as detailed in the Oracle CPU July 2026 advisory.
  • Limit inbound traffic to the T3 and IIOP ports used by WebCenter Enterprise Capture to a trusted subnet or specific IP addresses, effectively preventing unauthenticated external access.
  • Enforce strict authentication and role‑based access controls in WebCenter Enterprise Capture, ensuring that only authorized users can invoke sensitive operations.
  • Continuously monitor connection attempts and authentication logs for signs of unauthorized access or exploitation attempts, and investigate any anomalies promptly.

Generated by OpenCVE AI on August 4, 2026 at 17:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Attack Enables Full Takeover of Oracle WebCenter Enterprise Capture

Tue, 28 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover in Oracle WebCenter Enterprise Capture
Weaknesses CWE-284
CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover in Oracle WebCenter Enterprise Capture
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:16:17.616Z

Reserved: 2026-07-08T15:51:40.537Z

Link: CVE-2026-60446

cve-icon Vulnrichment

Updated: 2026-07-24T15:16:04.636Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:30:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function