Oracle's July 2026 Critical Patch Update discloses CVE-2026-60459, a CVSS 9.9 vulnerability in Oracle WebCenter Enterprise Capture that lets a low-privileged network attacker fully take over the product.
What Is It
CVE-2026-60459 is a critical vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware, specifically in the Client Bundle component. It is described as easily exploitable: a low-privileged attacker with network access over HTTP can compromise the software without user interaction. The flaw carries a CVSS 3.1 base score of 9.9 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, reflecting high impact to confidentiality, integrity, and availability.
Why It Matters
Successful exploitation can result in complete takeover of Oracle WebCenter Enterprise Capture. Critically, the vulnerability has a scope change: while the flaw resides in WebCenter Enterprise Capture, attacks may significantly impact additional products beyond the vulnerable component. Combined with low attack complexity, low required privileges, and no user interaction, this makes the flaw an attractive target. As of this writing, the supplied source material contains no CISA KEV entry, so active exploitation is not confirmed in these sources.
What's Vulnerable
The affected product is Oracle WebCenter Enterprise Capture, a component of Oracle Fusion Middleware. The supported versions listed as affected are:
- 12.2.1.4.0
- 14.1.2.0.0
Patch Status
The vulnerability was published on 2026-07-21 with an NVD status of "Received." Remediation is addressed through Oracle's July 2026 Critical Patch Update. Administrators should consult the Oracle Critical Patch Update advisory and apply the relevant fixes for the affected versions.
Sources
- Oracle Critical Patch Update Advisory (July 2026), https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60459, https://nvd.nist.gov/vuln/detail/CVE-2026-60459