Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the client bundle of Oracle WebCenter Enterprise Capture allows an attacker to connect to the RMI interfaces without authentication. By sending specially crafted requests, an unauthenticated remote user can gain control of the application, resulting in the exposure of all confidential data, modification of system state, and disruption of services. The vulnerability carries full confidentiality, integrity, and availability impacts as reflected in the CVSS vector.

Affected Systems

This weakness affects Oracle Corporation’s WebCenter Enterprise Capture, specifically versions 12.2.1.4.0 and 14.1.2.0.0. No additional products or versions were identified as impacted.

Risk and Exploitability

With a CVSS v3.1 base score of 9.8, the risk is critical. EPSS has not been published but the lack of an exploit restriction implies high exploitability. The vulnerability is not listed in CISA’s KEV catalog. Attackers who can reach the RMI ports from the network can exploit this weakness with no prior privileges, making it a high‑threat scenario.

Generated by OpenCVE AI on August 18, 2026 at 23:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch that addresses CVE-2026-60947 to WebCenter Enterprise Capture.
  • If a patch is unavailable, upgrade the product to a supported release that is not affected by the CVE.
  • If upgrading is not immediately possible, restrict network access to the RMI port using firewall rules or disable RMI altogether and monitor for suspicious activity.

Generated by OpenCVE AI on August 18, 2026 at 23:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated RMI Attack Enables Full Compromise of Oracle WebCenter Enterprise Capture
Weaknesses CWE-284
CWE-295

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:23.420Z

Reserved: 2026-07-08T15:51:55.603Z

Link: CVE-2026-60947

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:48.560

Modified: 2026-08-18T21:16:48.560

Link: CVE-2026-60947

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:30:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-295

    Improper Certificate Validation