Executive brief
Oracle WebCenter Enterprise Capture, a tool used for digitizing and processing business documents, contains a critical security vulnerability in its Client Bundle component. An attacker with basic network access can take full control of the system, potentially leading to the theft of sensitive documents, data corruption, or a total service shutdown. Because this component interacts with other systems, a successful attack could also allow the intruder to compromise additional parts of the corporate network.
Technical details
A critical vulnerability exists in the Client Bundle component of Oracle WebCenter Enterprise Capture (part of Oracle Fusion Middleware). The flaw is easily exploitable by a low-privileged attacker with network access via the T3 or IIOP protocols. Successful exploitation results in a complete takeover of the affected product (Confidentiality, Integrity, and Availability impacts). Notably, the vulnerability carries a scope change (S:C), meaning an attacker can impact resources beyond the security scope of WebCenter Enterprise Capture itself. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Initial publication of CVE-2026-60458 by Oracle and NVD.