Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to connect via the T3 or IIOP protocols to the Client Bundle component of Oracle WebCenter Enterprise Capture and execute arbitrary code. Successful exploitation results in the attacker taking full control of the application, compromising confidentiality, integrity, and availability of the entire system. The weakness is reflected in a CVSS 3.1 base score of 9.8, indicating a critical severity and the potential for full system takeover.

Affected Systems

The weakness affects Oracle WebCenter Enterprise Capture for the identified versions 12.2.1.4.0 and 14.1.2.0.0. No other versions or products are listed as impacted in the available data.

Risk and Exploitability

The CVSS score of 9.8 denotes a critical risk, while the EPSS score is not available and the vulnerability does not appear in the CISA KEV catalog. The attack vector is network based (T3 and IIOP) and requires no authentication, meaning an attacker with network access can immediately attempt exploitation. The high severity, lack of requirement for user interaction, and unrestricted attacker control make the risk of exploitation significant if the vulnerability remains unpatched.

Generated by OpenCVE AI on August 18, 2026 at 23:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch or upgrade to a fixed version of Oracle WebCenter Enterprise Capture.
  • Block or restrict the T3 and IIOP network ports from untrusted sources until the patch is applied to limit attacker reach.
  • Segregate WebCenter Enterprise Capture servers from the public network and enforce least‑privilege connectivity settings.

Generated by OpenCVE AI on August 18, 2026 at 23:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle WebCenter Enterprise Capture via T3/IIOP
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:21.195Z

Reserved: 2026-07-08T15:51:55.602Z

Link: CVE-2026-60921

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:47.710

Modified: 2026-08-18T21:16:47.710

Link: CVE-2026-60921

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:30:04Z

Weaknesses