Junglewise Threat Intelligence

CVE-2026-60456: Oracle WebCenter Enterprise Capture takeover in Client Bundle

CVE-2026-60456 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Technologies: Oracle WebCenter Enterprise Capture. Vendors: Oracle.

Executive brief

Oracle WebCenter Enterprise Capture, a tool used for digitizing and processing business documents, contains a critical vulnerability in its Client Bundle component. A user with low-level access to the network can exploit this flaw to take full control of the system. This could lead to the theft of sensitive business documents, disruption of document processing workflows, and potential unauthorized access to other connected corporate systems.

Technical details

A critical vulnerability exists in the Client Bundle component of Oracle WebCenter Enterprise Capture (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. The vulnerability is characterized by a 'scope change' (Status: C in CVSS), meaning an exploit can impact components beyond the immediate security scope of the WebCenter application. Successful exploitation allows for a complete compromise of confidentiality, integrity, and availability, effectively resulting in a total system takeover. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed: Initial advisory publication

References

Related threats