A critical (CVSS 9.9) vulnerability in Oracle WebCenter Enterprise Capture allows a low-privileged, remote attacker to fully take over the product and impact adjacent systems, addressed in Oracle's July 2026 Critical Patch Update.
What Is It
CVE-2026-60461 is a vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware, specifically in the Client Bundle component. It is described as an easily exploitable flaw that lets a low-privileged attacker with network access via the T3 or IIOP protocols compromise Oracle WebCenter Enterprise Capture. Successful attacks can result in a complete takeover of the product.
Oracle assigns a CVSS 3.1 base score of 9.9 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, reflecting high impacts to confidentiality, integrity, and availability.
Why It Matters
The flaw carries a scope change: although the vulnerability resides in Oracle WebCenter Enterprise Capture, Oracle warns that attacks may significantly impact additional products beyond the vulnerable component. Combined with low attack complexity, no user interaction, and only low privileges required over the network, this makes the issue especially dangerous in exposed Fusion Middleware environments. The high confidentiality, integrity, and availability impacts mean a successful attacker can read, alter, and disrupt affected systems.
What's Vulnerable
- Product: Oracle WebCenter Enterprise Capture (Oracle Fusion Middleware)
- Component: Client Bundle
- Affected versions: 12.2.1.4.0 and 14.1.2.0.0
- Attack path: Network access via T3, IIOP
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Administrators running the affected versions should apply the fixes referenced in the Oracle Critical Patch Update Advisory for July 2026. No CISA KEV entry confirming active exploitation was supplied for this CVE.
Sources
- NVD, CVE-2026-60461: https://nvd.nist.gov/vuln/detail/CVE-2026-60461
- Oracle Critical Patch Update Advisory (July 2026): https://www.oracle.com/security-alerts/cpujul2026.html