Oracle's July 2026 Critical Patch Update discloses CVE-2026-60456, a critical (CVSS 9.9) vulnerability in Oracle WebCenter Enterprise Capture that lets a low-privileged network attacker fully take over the product and pivot into other systems.
What Is It
CVE-2026-60456 is a vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware. Oracle rates it "easily exploitable," meaning a low-privileged attacker with network access over HTTP can compromise the product without user interaction. Successful attacks result in a complete takeover of Oracle WebCenter Enterprise Capture, with high impact to confidentiality, integrity, and availability.
Why It Matters
The vulnerability carries a CVSS 3.1 base score of 9.9, near the top of the scale, driven by low attack complexity, no required user interaction, and a scope change (CVSS vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). The scope change is the key detail: while the flaw resides in WebCenter Enterprise Capture, Oracle warns that attacks "may significantly impact additional products." That means a successful exploit is not contained to the vulnerable component and can spill over into connected systems, raising the blast radius considerably.
What's Vulnerable
Per Oracle, the affected supported versions of Oracle WebCenter Enterprise Capture are:
- 12.2.1.4.0
- 14.1.2.0.0
The vulnerable component is the Client Bundle, and the attack vector is HTTP over the network.
Patch Status
Oracle addresses CVE-2026-60456 in its July 2026 Critical Patch Update (published July 21, 2026). Organizations running the affected versions should apply the fixes from that CPU as the remediation path. There is no CISA KEV entry supplied for this CVE, so active exploitation is not confirmed in the source material; given the 9.9 severity and Oracle's "easily exploitable" assessment, prompt patching is warranted regardless.
Sources
- Oracle Critical Patch Update Advisory, July 2026, https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60456, https://nvd.nist.gov/vuln/detail/CVE-2026-60456