Junglewise Threat Intelligence

CVE-2026-60445: Oracle WebCenter Enterprise Capture takeover via Client Bundle

CVE-2026-60445 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Technologies: Oracle WebCenter Enterprise Capture. Vendors: Oracle.

Executive brief

Oracle WebCenter Enterprise Capture, a tool used for digitizing and processing business documents, contains a critical security vulnerability in its Client Bundle component. A user with low-level access to the network can exploit this flaw to take complete control of the system. This could lead to the theft of sensitive business documents, disruption of document processing workflows, and potential unauthorized access to other connected corporate systems.

Technical details

A vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture (part of Oracle Fusion Middleware) allows for a complete system takeover. The flaw is exploitable by a low-privileged attacker with network access via the T3 or IIOP protocols. The vulnerability is characterized by a 'scope change' (Status: C in CVSS), meaning a successful exploit can impact resources beyond the security scope of the WebCenter Enterprise Capture application itself. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats