SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60456 2026-07-21

CVE-2026-60456: Critical Takeover Flaw in Oracle WebCenter Enterprise Capture

"Oracle's July 2026 Critical Patch Update discloses CVE-2026-60456, a critical (CVSS 9.9) vulnerability in Oracle WebCenter Enterprise Capture that lets a low-privileged network attacker fully take over the product and…"

Oracle's July 2026 Critical Patch Update discloses CVE-2026-60456, a critical (CVSS 9.9) vulnerability in Oracle WebCenter Enterprise Capture that lets a low-privileged network attacker fully take over the product and pivot into other systems.

What Is It

CVE-2026-60456 is a vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware. Oracle rates it "easily exploitable," meaning a low-privileged attacker with network access over HTTP can compromise the product without user interaction. Successful attacks result in a complete takeover of Oracle WebCenter Enterprise Capture, with high impact to confidentiality, integrity, and availability.

Why It Matters

The vulnerability carries a CVSS 3.1 base score of 9.9, near the top of the scale, driven by low attack complexity, no required user interaction, and a scope change (CVSS vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). The scope change is the key detail: while the flaw resides in WebCenter Enterprise Capture, Oracle warns that attacks "may significantly impact additional products." That means a successful exploit is not contained to the vulnerable component and can spill over into connected systems, raising the blast radius considerably.

What's Vulnerable

Per Oracle, the affected supported versions of Oracle WebCenter Enterprise Capture are:

The vulnerable component is the Client Bundle, and the attack vector is HTTP over the network.

Patch Status

Oracle addresses CVE-2026-60456 in its July 2026 Critical Patch Update (published July 21, 2026). Organizations running the affected versions should apply the fixes from that CPU as the remediation path. There is no CISA KEV entry supplied for this CVE, so active exploitation is not confirmed in the source material; given the 9.9 severity and Oracle's "easily exploitable" assessment, prompt patching is warranted regardless.

Sources