Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker with network access to the T3 and IIOP interfaces can exploit a Weak Authentication or Authorization flaw (CWE-284) in the client bundle of Oracle WebCenter Enterprise Capture, leading to complete takeover of the application. The vulnerability results in confidentiality, integrity, and availability loss, as described by the CVSS 3.1 score of 9.8, and allows the attacker to execute arbitrary code in the context of the application.

Affected Systems

Oracle Corporation’s WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are identified as affected. These versions are part of Oracle Fusion Middleware and are typically deployed in enterprise content capture scenarios.

Risk and Exploitability

The CVSS base score of 9.8 indicates a critical risk, and the EPSS score of < 1% indicates a very low exploitation probability. Nonetheless, the vulnerability is easily exploitable with network connectivity to T3 and IIOP ports, and there is no mention of the vulnerability being listed in KEV. Attackers could therefore mount attacks without authentication, leading to full control over the application.

Generated by OpenCVE AI on August 21, 2026 at 14:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebCenter Enterprise Capture patch that removes the authentication bypass flaw
  • Configure firewall or network segmentation to block untrusted inbound traffic on T3 and IIOP ports as a temporary safeguard
  • Reconfigure the application to enforce strong authentication and role-based access controls in line with CWE‑284 mitigation practices

Generated by OpenCVE AI on August 21, 2026 at 14:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle WebCenter Enterprise Capture

Fri, 21 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T03:56:57.564Z

Reserved: 2026-07-08T15:51:55.605Z

Link: CVE-2026-60971

cve-icon Vulnrichment

Updated: 2026-08-20T19:31:09.720Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:49.727

Modified: 2026-08-21T15:16:29.270

Link: CVE-2026-60971

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T14:45:16Z

Weaknesses