Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw exists in the Client Bundle component of Oracle WebCenter Enterprise Capture, where insufficient access control permits a low‑privileged user with network access over HTTP to obtain full control of the application. The attacker can read, modify, or delete captured data, submit new captures, and reconfigure the system, leading to a complete takeover that compromises confidentiality, integrity, and availability.

Affected Systems

Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected; the vulnerability resides in the Client Bundle component.

Risk and Exploitability

The CVSS v3.1 base score of 8.8 indicates high severity across all impact dimensions. The EPSS score of < 1% indicates only a very low but non‑zero likelihood of exploitation in active campaigns. The vulnerability is not listed in the CISA KEV catalog. Attacks require only network access via HTTP and a low‑privileged user, with no user interaction needed, lowering the entry threshold for adversaries.

Generated by OpenCVE AI on August 4, 2026 at 16:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch for CVE-2026-61099 to the affected versions 12.2.1.4.0 and 14.1.2.0.0.
  • Restrict HTTP exposure of the Client Bundle endpoints to trusted internal hosts or VPN‑protected networks.
  • Deploy network‑level controls such as firewalls or a web‑application firewall to detect and block anomalous requests targeting the Client Bundle.

Generated by OpenCVE AI on August 4, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Network Attack Compromising Oracle WebCenter Enterprise Capture Client Bundle

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution Vulnerability in Oracle WebCenter Enterprise Capture Leading to Full Takeover

Mon, 27 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution Vulnerability in Oracle WebCenter Enterprise Capture Leading to Full Takeover

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:26:23.371Z

Reserved: 2026-07-08T15:51:55.613Z

Link: CVE-2026-61099

cve-icon Vulnrichment

Updated: 2026-07-23T19:26:17.976Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:30:11Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function