Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle WebCenter Enterprise Capture is vulnerable to an unauthenticated remote attack that enables an attacker with network access via T3 or IIOP to compromise the system. The flaw lies in the client bundle component, allowing a remote attacker to execute arbitrary actions and ultimately take over the application. The weakness can be categorized as an improper authentication failure, which can lead to total confidentiality, integrity, and availability loss.

Affected Systems

Oracle WebCenter Enterprise Capture from Oracle Corporation, specifically versions 12.2.1.4.0 and 14.1.2.0.0, are affected by this vulnerability.

Risk and Exploitability

The CVSS 3.1 score of 9.8 indicates a critical severity. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network-based and requires no user interaction, giving an unauthenticated attacker with connectivity over T3 or IIOP a pathway to compromise the application. Given the high CVSS score but low EPSS, the overall risk of real-world attacks remains moderate, though the potential impact is severe.

Generated by OpenCVE AI on August 21, 2026 at 14:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch for WebCenter Enterprise Capture 12.2.1.4.0 and 14.1.2.0.0 as detailed in the Oracle advisory.
  • If a patch cannot be applied immediately, block or disable T3 and IIOP ports to prevent unauthenticated network access to the client bundle.
  • Configure firewall rules to limit inbound traffic on T3/IIOP to trusted IP ranges only.
  • Restore the client bundle component from verified backups or validate its checksums to ensure no tampering has occurred.

Generated by OpenCVE AI on August 21, 2026 at 14:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Attacker Can Compromise Oracle WebCenter Enterprise Capture

Fri, 21 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T03:56:56.448Z

Reserved: 2026-07-08T15:51:55.605Z

Link: CVE-2026-60970

cve-icon Vulnrichment

Updated: 2026-08-20T19:31:03.703Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:49.613

Modified: 2026-08-21T15:25:16.963

Link: CVE-2026-60970

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T15:00:11Z

Weaknesses