Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Client Bundle component of Oracle WebCenter Enterprise Capture and enables a low‑privileged attacker with network access through T3 or IIOP to compromise the application. Attackers can achieve full takeover of the product, leading to complete loss of confidentiality, integrity, and availability. The impact can extend beyond the WebCenter product, potentially affecting other Oracle Fusion Middleware components.

Affected Systems

Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability is present in the fusion middleware of these releases, and because of the scope change described, many other Oracle Fusion Middleware applications may also be at risk if they rely on WebCenter components.

Risk and Exploitability

The CVSS v3.1 score of 9.9 marks it as Critical, with network-based attacks requiring only low privileges and no user interaction. The EPSS score is below 1 %, indicating a low probability of exploitation in the wild, yet the vulnerability is not listed in CISA’s KEV catalogue. The easy‑to‑exploit nature and its potential to compromise multiple products make it a high priority for remediation, even if active exploit activity has not yet been observed.

Generated by OpenCVE AI on August 4, 2026 at 03:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Security Patch for WebCenter Enterprise Capture 12.2.1.4.0 and 14.1.2.0.0 to fix the vulnerability.
  • Block inbound T3 and IIOP traffic to the WebCenter application from untrusted networks or restrict to trusted IP ranges.
  • Monitor network traffic and application logs for anomalous activity that may indicate attempted exploitation.

Generated by OpenCVE AI on August 4, 2026 at 03:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Takeover via Client Bundle in Oracle WebCenter Enterprise Capture

Thu, 30 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Takeover via Client Bundle in Oracle WebCenter Enterprise Capture

Tue, 28 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via T3/IIOP in Oracle WebCenter Enterprise Capture
Weaknesses CWE-269

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via T3/IIOP in Oracle WebCenter Enterprise Capture
Weaknesses CWE-269
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:28:58.627Z

Reserved: 2026-07-08T15:51:40.538Z

Link: CVE-2026-60457

cve-icon Vulnrichment

Updated: 2026-07-24T14:28:48.684Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:00:03Z

Weaknesses