SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60461 2026-07-21

CVE-2026-60461: Critical Takeover Flaw in Oracle WebCenter Enterprise Capture

"A critical (CVSS 9.9) vulnerability in Oracle WebCenter Enterprise Capture allows a low-privileged, remote attacker to fully take over the product and impact adjacent systems, addressed in Oracle's July 2026 Critical…"

A critical (CVSS 9.9) vulnerability in Oracle WebCenter Enterprise Capture allows a low-privileged, remote attacker to fully take over the product and impact adjacent systems, addressed in Oracle's July 2026 Critical Patch Update.

What Is It

CVE-2026-60461 is a vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware, specifically in the Client Bundle component. It is described as an easily exploitable flaw that lets a low-privileged attacker with network access via the T3 or IIOP protocols compromise Oracle WebCenter Enterprise Capture. Successful attacks can result in a complete takeover of the product.

Oracle assigns a CVSS 3.1 base score of 9.9 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, reflecting high impacts to confidentiality, integrity, and availability.

Why It Matters

The flaw carries a scope change: although the vulnerability resides in Oracle WebCenter Enterprise Capture, Oracle warns that attacks may significantly impact additional products beyond the vulnerable component. Combined with low attack complexity, no user interaction, and only low privileges required over the network, this makes the issue especially dangerous in exposed Fusion Middleware environments. The high confidentiality, integrity, and availability impacts mean a successful attacker can read, alter, and disrupt affected systems.

What's Vulnerable

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Administrators running the affected versions should apply the fixes referenced in the Oracle Critical Patch Update Advisory for July 2026. No CISA KEV entry confirming active exploitation was supplied for this CVE.

Sources