Oracle disclosed CVE-2026-60445, a critical (CVSS 9.9) vulnerability in Oracle WebCenter Enterprise Capture that lets a low-privileged network attacker fully take over the product and spill into adjacent systems.
What Is It
The flaw resides in the Client Bundle component of Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware. An easily exploitable weakness allows a low-privileged attacker with network access via the T3 and IIOP protocols to compromise the product. Successful exploitation results in complete takeover of Oracle WebCenter Enterprise Capture. The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, reflecting network attack vector, low complexity, and no user interaction required.
Why It Matters
The vulnerability carries a base score of 9.9, near the maximum, driven by high impact to confidentiality, integrity, and availability. Critically, the scope is marked changed: while the vulnerability lives in WebCenter Enterprise Capture, attacks may significantly impact additional products beyond the vulnerable component. Combined with low attack complexity and no required user interaction, this is a high-value target for attackers who already hold minimal network access.
What's Vulnerable
The affected product is Oracle WebCenter Enterprise Capture (Oracle Corporation), a component of Oracle Fusion Middleware. Supported versions confirmed affected are:
- 12.2.1.4.0
- 14.1.2.0.0
Exploitation is reachable over the T3 and IIOP protocols.
Patch Status
The vulnerability was published July 21, 2026, with NVD status "Received." Oracle addressed it in the July 2026 Critical Patch Update. Administrators running the affected 12.2.1.4.0 and 14.1.2.0.0 versions should apply the fixes referenced in Oracle's Critical Patch Update advisory. No CISA KEV entry accompanies this record, so there is no confirmation of active exploitation in the supplied source material at this time.
Sources
- Oracle Critical Patch Update Advisory, July 2026, https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60445, https://nvd.nist.gov/vuln/detail/CVE-2026-60445