Junglewise Threat Intelligence

CVE-2026-60524: Oracle WebCenter Enterprise Capture remote takeover in Client Bundle

CVE-2026-60524 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Technologies: Oracle WebCenter Enterprise Capture. Vendors: Oracle.

Executive brief

Oracle WebCenter Enterprise Capture, a tool used for digitizing and managing business documents, contains a critical security vulnerability in its Client Bundle component. An attacker with low-level network access can exploit this flaw to take complete control of the system. This could lead to the theft of sensitive business documents, disruption of document processing workflows, and potential unauthorized access to other connected corporate systems.

Technical details

This vulnerability exists in the Client Bundle component of Oracle WebCenter Enterprise Capture (versions 12.2.1.4.0 and 14.1.2.0.0). It is easily exploitable by a low-privileged attacker with network access using the T3 or IIOP protocols. The flaw is characterized by a scope change (S:C), meaning a successful exploit can impact products beyond the immediate component, potentially leading to a full compromise of the host environment. The vulnerability has been assigned a CVSS 3.1 base score of 9.9, reflecting high impacts on confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats