Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle WebCenter Enterprise Capture is vulnerable to a highly exploitable flaw that allows a low privileged attacker with network access via HTTP to take full control of the system. An attacker can compromise the confidentiality, integrity, and availability of the product, resulting in a complete takeover. The weakness resides in the Client Bundle component and can lead to execution of arbitrary code with local privileges on the host.

Affected Systems

Oracle WebCenter Enterprise Capture, versions 12.2.1.4.0 and 14.1.2.0 issue is specific to these builds, but compromise of the capture component may also impact other Oracle Fusion Middleware products due to scope changes noted in the advisory.

Risk and Exploitability

The CVSS 3.1 base score of 9.9 reflects a high impact with easy exploitation (low authentication required). The attack vector is likely remote over HTTP, and the estimated EPSS score of less than 1% indicates a low but nonzero probability of exploitation. The CVSS vector indicates a scope change (S:C), which may affect other components of the application. The vulnerability is not yet listed in CISA's KEV catalog, but the severity and potential for takeover make it a critical risk for any impacted environment.

Generated by OpenCVE AI on August 4, 2026 at 03:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch that fixes the access control flaw (CWE-284) in the Client Bundle component of Oracle WebCenter Enterprise Capture.
  • If patching cannot be performed immediately, deploy an unaffected version or apply an equivalent mitigation that removes the vulnerable code.
  • Enforce network segmentation and limit external HTTP access to the WebCenter Enterprise Capture service via firewall rules or IP whitelisting to reduce the chance of an attacker exploiting the access control weakness.

Generated by OpenCVE AI on August 4, 2026 at 03:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution and Full Takeover Vulnerability in Oracle WebCenter Enterprise Capture

Tue, 28 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Oracle WebCenter Enterprise Capture Remote Code Execution in Client Bundle
Weaknesses CWE-78

Fri, 24 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Oracle WebCenter Enterprise Capture Remote Code Execution in Client Bundle
Weaknesses CWE-78

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:33:45.216Z

Reserved: 2026-07-08T15:51:40.538Z

Link: CVE-2026-60459

cve-icon Vulnrichment

Updated: 2026-07-24T14:33:33.553Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:00:03Z

Weaknesses