Junglewise Threat Intelligence

CVE-2026-60457: Oracle WebCenter Enterprise Capture takeover in Client Bundle

CVE-2026-60457 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Technologies: Oracle WebCenter Enterprise Capture. Vendors: Oracle.

Executive brief

Oracle WebCenter Enterprise Capture, a tool used for digitizing and processing business documents, contains a critical security vulnerability in its Client Bundle component. An attacker with basic user credentials can exploit this flaw over the network to gain full control of the system. This could lead to the theft of sensitive business documents, disruption of document processing workflows, and potential unauthorized access to other connected corporate systems.

Technical details

A vulnerability exists in the Client Bundle component of Oracle WebCenter Enterprise Capture (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable by a low-privileged attacker with network access via the T3 or IIOP protocols. The vulnerability is characterized by a scope change (S:C), meaning a successful exploit can impact components beyond the immediate security scope of the affected product. Successful exploitation results in a complete compromise of confidentiality, integrity, and availability (takeover). Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60457
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats