A critical (CVSS 9.9) vulnerability in Oracle WebCenter Enterprise Capture lets a low-privileged network attacker fully take over the product and pivot into other systems, addressed in Oracle's July 2026 Critical Patch Update.
What Is It
CVE-2026-60457 is a critical vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is easily exploitable and allows a low-privileged attacker with network access via the T3 or IIOP protocols to compromise the product. Successful exploitation can result in complete takeover of Oracle WebCenter Enterprise Capture. The issue carries a CVSS 3.1 base score of 9.9 with the vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H.
Why It Matters
The vulnerability combines network reachability, low attack complexity, and only low privileges, no user interaction required, making it attractive to attackers. Critically, the scope is "changed": while the flaw resides in WebCenter Enterprise Capture, Oracle warns that attacks "may significantly impact additional products." A successful attack yields high impact to confidentiality, integrity, and availability, meaning an attacker can read data, alter it, and disrupt service, potentially reaching beyond the initially compromised component.
What's Vulnerable
Per the NVD record, the affected supported versions are:
- Oracle WebCenter Enterprise Capture 12.2.1.4.0
- Oracle WebCenter Enterprise Capture 14.1.2.0.0
The exposure stems from the Client Bundle component and is reachable over the T3 and IIOP protocols.
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running the affected versions should apply the fixes referenced in Oracle's advisory. No CISA KEV entry confirming active exploitation was supplied with this record.
Sources
- Oracle Critical Patch Update Advisory; July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60457: https://nvd.nist.gov/vuln/detail/CVE-2026-60457