Oracle has disclosed CVE-2026-61100, a critical (CVSS 9.8) flaw in Oracle WebCenter Enterprise Capture that lets an unauthenticated attacker take over the product over the network.
What Is It
CVE-2026-61100 is a vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware, specifically in the Client Bundle component. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise the product. A successful attack can result in a complete takeover of Oracle WebCenter Enterprise Capture.
The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting high impacts to confidentiality, integrity, and availability.
Why It Matters
The combination of network attack vector, low attack complexity, and no required privileges or user interaction means an attacker needs nothing more than HTTP access to a vulnerable instance. Because a successful attack yields full takeover of the product, with high confidentiality, integrity, and availability impact, exposed instances represent a serious risk to any environment running affected versions.
What's Vulnerable
Per Oracle, the affected supported versions are:
- Oracle WebCenter Enterprise Capture 12.2.1.4.0
- Oracle WebCenter Enterprise Capture 14.1.2.0.0
The vulnerable component is the Client Bundle within Oracle Fusion Middleware.
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running the affected versions should apply the fixes referenced in the Oracle Critical Patch Update Advisory (cpujul2026). This CVE does not appear in the supplied CISA KEV data, so there is no confirmation of active exploitation in the provided sources.