Oracle disclosed a CVSS 9.9 vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture that lets an unauthenticated remote attacker compromise the product over HTTP and impact adjacent systems.
What Is It
CVE-2026-60916 is a vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware, specifically the Client Bundle component. Oracle rates it "easily exploitable," meaning an unauthenticated attacker with network access via HTTP can compromise the product without user interaction or prior privileges.
The CVSS 3.1 base score is 9.9 (Critical), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L. The scope-changed flag is the notable part: although the flaw lives in WebCenter Enterprise Capture, Oracle states that attacks may significantly impact additional products beyond the vulnerable component's security boundary.
Why It Matters
Successful exploitation grants unauthorized creation, deletion, or modification access to critical data, or to all data accessible to WebCenter Enterprise Capture. Attackers also gain unauthorized read access to a subset of accessible data and the ability to cause a partial denial of service against the product.
The combination of no authentication, low attack complexity, network reach over HTTP, and a changed scope puts this at the top of the patching queue for any Fusion Middleware estate. The integrity impact is rated High, meaning data manipulation, not just theft, is the primary risk.
There is no CISA KEV entry for this CVE in the supplied data, so active exploitation is not confirmed at this time.
What's Vulnerable
Vendor: Oracle Corporation Product: Oracle WebCenter Enterprise Capture (Oracle Fusion Middleware) Component: Client Bundle
Affected supported versions: - 12.2.1.4.0 - 14.1.2.0.0
Patch Status
Oracle ships fixes for Fusion Middleware through its quarterly Critical Patch Update program, which releases in January, April, July, and October; there is no standalone August release. The July 2026 Critical Patch Update is the relevant advisory cycle for this disclosure, and administrators should confirm the exact advisory and patch number against Oracle's Security Alerts index before deploying. Apply the applicable patch to affected 12.2.1.4.0 and 14.1.2.0.0 deployments. No specific CISA-mandated remediation deadline is present in the supplied data.
The NVD record status is "Received" as of 2026-08-18, so enrichment such as CWE mapping and CPE data is still pending.
Sources
- Oracle Critical Patch Update Advisory; July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- Oracle Security Alerts index (confirm current advisory): https://www.oracle.com/security-alerts/
- NVD, CVE-2026-60916: https://nvd.nist.gov/vuln/detail/CVE-2026-60916