Junglewise Threat Intelligence

CVE-2026-60461: Oracle WebCenter Enterprise Capture remote code execution in Client Bundle

CVE-2026-60461 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Technologies: Oracle WebCenter Enterprise Capture. Vendors: Oracle.

Executive brief

Oracle WebCenter Enterprise Capture, a tool used for high-volume document scanning and processing, contains a critical security vulnerability in its Client Bundle component. A low-privileged user with network access can exploit this flaw to take full control of the system. This could lead to the theft of sensitive documents, disruption of business operations, and potential unauthorized access to other connected corporate systems.

Technical details

This vulnerability exists in the Client Bundle component of Oracle WebCenter Enterprise Capture (versions 12.2.1.4.0 and 14.1.2.0.0). It is easily exploitable by a low-privileged attacker with network access using the T3 or IIOP protocols. The flaw is characterized by a scope change (CVSS S:C), meaning a successful exploit can impact security beyond the immediate Oracle WebCenter Enterprise Capture environment. Successful exploitation results in a complete takeover of the affected product, impacting confidentiality, integrity, and availability. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats