Oracle disclosed CVE-2026-60446, a CVSS 9.8 flaw in Oracle WebCenter Enterprise Capture that lets an unauthenticated attacker fully compromise the product over the network.
What Is It
CVE-2026-60446 is a critical vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware, specifically in the Client Bundle component. It is easily exploitable and allows an unauthenticated attacker with network access via the T3 and IIOP protocols to compromise the product. A successful attack can result in complete takeover of Oracle WebCenter Enterprise Capture. The flaw carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Why It Matters
This vulnerability requires no authentication, no privileges, and no user interaction, and it is exploitable remotely over the network with low attack complexity. The impact spans all three CVSS dimensions, confidentiality, integrity, and availability are each rated HIGH, because successful exploitation yields full takeover of the affected product. That combination of trivial exploitability and total compromise places it at the top of the severity scale.
What's Vulnerable
The affected product is Oracle WebCenter Enterprise Capture (vendor: Oracle Corporation). The supported versions listed as affected are:
- 12.2.1.4.0
- 14.1.2.0.0
The attack surface is exposure of the T3 and IIOP protocols to untrusted networks.
Patch Status
Oracle addressed this issue in its July 2026 Critical Patch Update. Organizations running the affected versions should apply the fixes referenced in the Oracle Critical Patch Update Advisory for July 2026. The supplied source material does not include a CISA KEV entry for this CVE, so there is no confirmation of active exploitation in the provided data.
Sources
- Oracle Critical Patch Update Advisory; July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60446: https://nvd.nist.gov/vuln/detail/CVE-2026-60446