Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the client bundle of Oracle WebCenter Enterprise Capture and represents an access control flaw (CWE-284) that permits a low‑privileged user with network access over the T3 or IIOP protocols to compromise the application. Successful exploitation can result in full takeover, leading to disclosure, modification, or denial of confidentiality, integrity and availability.

Affected Systems

Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These releases are part of Oracle Fusion Middleware. Since the vulnerability can change scope, other Oracle Fusion Middleware components may also be impacted even if they are not listed directly.

Risk and Exploitability

The CVSS base score of 9.9 highlights critical severity. With an EPSS score below 1%, the likelihood of immediate exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack can be carried out automatically over the network using T3 or IIOP, requiring only low privileges and no user interaction.

Generated by OpenCVE AI on August 4, 2026 at 03:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade for WebCenter Enterprise Capture as detailed in Oracle's July 2026 CPU advisory to eliminate the vulnerable client bundle.
  • Block or firewall the T3 and IIOP ports so that only trusted hosts within the corporate network can reach the WebCenter Enterprise Capture instance.
  • Implement network segmentation or dedicated firewall rules around the WebCenter Enterprise Capture deployment to mitigate potential lateral movement if the system is compromised.

Generated by OpenCVE AI on August 4, 2026 at 03:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Client Bundle in Oracle WebCenter Enterprise Capture

Tue, 28 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Remote takeover of Oracle WebCenter Enterprise Capture via T3/IIOP exploitation
Weaknesses CWE-287

Fri, 24 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Remote takeover of Oracle WebCenter Enterprise Capture via T3/IIOP exploitation
Weaknesses CWE-287

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T18:12:48.844Z

Reserved: 2026-07-08T15:51:40.542Z

Link: CVE-2026-60524

cve-icon Vulnrichment

Updated: 2026-07-24T18:12:43.843Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:45:03Z

Weaknesses