Oracle's July 2026 Critical Patch Update discloses CVE-2026-60524, a critical (CVSS 9.9) vulnerability in Oracle WebCenter Enterprise Capture that lets a low-privileged network attacker fully take over the product and impact other systems.
What Is It
CVE-2026-60524 is a vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware. It is described as easily exploitable, allowing a low-privileged attacker with network access via the T3 or IIOP protocols to compromise the product. Successful attacks can result in a complete takeover of Oracle WebCenter Enterprise Capture.
The issue carries a CVSS 3.1 base score of 9.9 (CRITICAL) with the vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, reflecting network attack vector, low complexity, low privileges required, no user interaction, and high confidentiality, integrity, and availability impact.
Why It Matters
A defining feature of this flaw is scope change (S:C): while the vulnerability lives in Oracle WebCenter Enterprise Capture, Oracle notes that attacks "may significantly impact additional products." That blast radius, combined with low attack complexity and only low privileges required, is what pushes the score to 9.9; near the maximum. An attacker who reaches the T3 or IIOP interface can achieve full compromise of confidentiality, integrity, and availability, and potentially pivot beyond the vulnerable product itself.
What's Vulnerable
- Product: Oracle WebCenter Enterprise Capture (Oracle Fusion Middleware)
- Component: Client Bundle
- Affected versions: 12.2.1.4.0 and 14.1.2.0.0
- Attack surface: Network access via T3, IIOP
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Administrators should apply the fixes referenced in the Oracle Critical Patch Update Advisory for July 2026. The supplied source material contains no CISA KEV entry for this CVE, so there is no confirmation of active exploitation at this time.