A critical (CVSS 9.9) vulnerability in Oracle WebCenter Enterprise Capture lets a low-privileged, network-based attacker take over the product and impact adjacent systems through a scope change.
What Is It
CVE-2026-60447 is a vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware. Oracle rates it as easily exploitable: an attacker with only low privileges and network access over HTTP can compromise the product with no user interaction. Successful exploitation can result in full takeover of Oracle WebCenter Enterprise Capture. Because the vulnerability carries a scope change (CVSS S:C), attacks may significantly impact additional products beyond the vulnerable component itself.
Why It Matters
The flaw earns a CVSS 3.1 base score of 9.9 (CRITICAL), with HIGH impact to confidentiality, integrity, and availability. The vector, AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, reflects a low-complexity, network-reachable attack requiring only minimal privileges. The combination of easy exploitability, no required user interaction, and a scope change that can spill damage into neighboring products makes this a high-priority concern for any organization running the affected middleware.
What's Vulnerable
- Product: Oracle WebCenter Enterprise Capture (Oracle Fusion Middleware)
- Component: Client Bundle
- Affected versions: 12.2.1.4.0 and 14.1.2.0.0
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running the affected versions should apply the fixes documented in the Oracle Critical Patch Update advisory. This CVE is not listed in the supplied CISA KEV data, so there is no confirmation of active exploitation at this time.