SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60946 2026-08-18

Oracle WebCenter Enterprise Capture Hit With 9.8 Unauthenticated RMI Takeover (CVE-2026-60946)

"Oracle disclosed a critical, unauthenticated remote takeover flaw in the Client Bundle component of Oracle WebCenter Enterprise Capture, scoring CVSS 9.8 and reachable over RMI with no credentials or user interaction."

Oracle disclosed a critical, unauthenticated remote takeover flaw in the Client Bundle component of Oracle WebCenter Enterprise Capture, scoring CVSS 9.8 and reachable over RMI with no credentials or user interaction.

What Is It

CVE-2026-60946 is a vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware, specifically the Client Bundle component. Oracle describes it as an easily exploitable flaw that allows an unauthenticated attacker with network access via RMI to compromise Oracle WebCenter Enterprise Capture. Successful attacks result in full takeover of the product.

The CVSS 3.1 base score is 9.8 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low attack complexity, no privileges required, no user interaction, and high impact to confidentiality, integrity, and availability. Exploitability subscore is 3.9, the maximum, and impact subscore is 5.9.

Why It Matters

Every barrier that normally slows an attacker is absent here. There is no authentication requirement, no user interaction, no elevated privilege prerequisite, and Oracle itself uses the phrase "easily exploitable." The outcome is not data disclosure or a crash; it is takeover of the Capture instance.

The exposure hinges on RMI reachability. Any WebCenter Enterprise Capture deployment whose RMI listener is reachable from an untrusted network segment should be treated as directly exposed.

CISA has not added CVE-2026-60946 to the Known Exploited Vulnerabilities catalog; no KEV entry was supplied and no active exploitation is confirmed in the available data.

What's Vulnerable

Vendor: Oracle Corporation Product: Oracle WebCenter Enterprise Capture (Oracle Fusion Middleware) Component: Client Bundle

Affected supported versions:

No CPE match data was published with the record at time of writing.

Patch Status

No patch is confirmed available for this CVE at time of writing.

The vulnerability was published 2026-08-18 with a vulnStatus of "Received," meaning NVD analysis was still pending and no vendor patch reference had been attached to the record.

Oracle ships Critical Patch Updates on a fixed quarterly schedule, January, April, July, and October, so there is no August release. The July 2026 Critical Patch Update predates this CVE's publication and is not documented as carrying a fix for it; operators should not read it as remediation for CVE-2026-60946. On the normal cadence, the earliest scheduled vehicle for a fix is the October 2026 Critical Patch Update, unless Oracle issues an out-of-cycle Security Alert sooner. Watch Oracle's security alerts page and the NVD record for a vendor patch reference to appear.

Until a fix ships, network controls are the only available mitigation. Operators running 12.2.1.4.0 or 14.1.2.0.0 should restrict RMI access to trusted networks, the RMI listener should not be reachable from untrusted segments under any configuration, and monitor RMI listener access for anomalous connections. No CISA-mandated remediation deadline exists, as the CVE is not in KEV.

Sources