Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Client Bundle component of Oracle WebCenter Enterprise Capture and allows an unauthenticated network attacker to connect via the T3 or IIOP protocols. By exploiting the missing authentication flaw (CWE-306), the attacker can fully compromise the application, gaining control that threatens confidentiality, integrity, and availability. This flaw is manifested as an authentication bypass that grants complete takeover of the affected instance.

Affected Systems

Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The vulnerability impacts systems running these releases of Oracle Fusion Middleware.

Risk and Exploitability

The CVSS 3.1 base score of 9.8 classifies this issue as critical, with no privileges required and no user interaction needed. The EPSS score of less than 1% indicates that widespread exploitation is currently limited, yet the vulnerability is not listed in CISA KEV. An attacker only needs basic network access to the exposed T3 or IIOP endpoints to trigger the exploit, making it highly addressable with direct reconnaissance.

Generated by OpenCVE AI on August 4, 2026 at 17:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 security update for WebCenter Enterprise Capture 12.2.1.4.0 and 14.1.2.0.0 as published in the Oracle advisory.
  • Restrict network traffic by blocking inbound T3 and IIOP connections from untrusted networks to the WebCenter servers.
  • Ensure that the application is not reachable over T3 or IIOP from external sources by configuring firewall rules or network segmentation.

Generated by OpenCVE AI on August 4, 2026 at 17:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Access to Oracle WebCenter Enterprise Capture Allows Full Compromise via T3 and IIOP

Tue, 28 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via T3 or IIOP in Oracle WebCenter Enterprise Capture
Weaknesses CWE-284
CWE-287

Fri, 24 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via T3 or IIOP in Oracle WebCenter Enterprise Capture
Weaknesses CWE-284
CWE-287

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:34:25.112Z

Reserved: 2026-07-08T15:51:40.538Z

Link: CVE-2026-60460

cve-icon Vulnrichment

Updated: 2026-07-24T14:34:18.916Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function