Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Oracle WebCenter Enterprise Capture client bundle allows an attacker who can reach the system via the T3 or IIOP protocols to gain full control of the application, compromising confidentiality, integrity, and availability. The issue is classified as a Remote Code Execution scenario with the potential to affect other dependent products because the exploit can change the overall scope of compromise. The CVE demonstrates that even a low‑privileged attacker can execute arbitrary code if this flaw is present, emphasizing the severity of the attack.

Affected Systems

Oracle WebCenter Enterprise Capture, versions 12.2.1.4.0 and 14.1.2.0.0. These are the only affected releases according to the CNA data, and the product belongs to the Oracle Fusion Middleware suite.

Risk and Exploitability

With a CVSS v3.1 score of 9.9, the vulnerability represents a critical level of risk. The EPSS score is below 1%, indicating that the probability of exploitation in the wild is low, and the vulnerability is not currently listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote network access via T3 or IIOP, requiring only low privileges, which allows an attacker to bypass authentication controls and execute arbitrary code.

Generated by OpenCVE AI on August 2, 2026 at 22:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s latest security patch for WebCenter Enterprise Capture 12.2.1.4.0 and 14.1.2.0.0 or upgrade to a non‑affected version
  • Disable or restrict network access to the T3 and IIOP ports used by the client bundle to limit exposure
  • Monitor incoming T3/IIOP traffic for anomalous activity and block malicious connection attempts
  • Implement network segmentation to isolate WebCenter Enterprise Capture from other mission critical systems

Generated by OpenCVE AI on August 2, 2026 at 22:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution Vulnerability in Oracle WebCenter Enterprise Capture Client Bundle
Weaknesses CWE-20
CWE-79
CWE-89

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution Vulnerability in Oracle WebCenter Enterprise Capture Client Bundle
Weaknesses CWE-20
CWE-79
CWE-89

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:35:49.508Z

Reserved: 2026-07-08T15:51:40.538Z

Link: CVE-2026-60461

cve-icon Vulnrichment

Updated: 2026-07-24T14:35:43.040Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function