Junglewise Threat Intelligence

CVE-2026-60459: Oracle WebCenter Enterprise Capture compromise in Client Bundle

CVE-2026-60459 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Technologies: Oracle WebCenter Enterprise Capture. Vendors: Oracle.

Executive brief

Oracle WebCenter Enterprise Capture, a tool used for digitizing and managing business documents, contains a critical security vulnerability in its Client Bundle component. An attacker with low-level access to the network can exploit this flaw to take complete control of the system. Because this vulnerability allows an attacker to move beyond the affected application, it poses a significant risk to other connected corporate systems and data integrity.

Technical details

A critical vulnerability exists in the Client Bundle component of Oracle WebCenter Enterprise Capture (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. The vulnerability is characterized by a CVSS 3.1 score of 9.9, notably involving a 'Scope Change' (S:C), meaning a successful exploit can impact resources beyond the security scope of the WebCenter application itself. Successful exploitation can lead to a complete takeover of the product, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation.

Affected products

  • Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats