SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61100 2026-07-21

CVE-2026-61100: Critical Unauthenticated Takeover in Oracle WebCenter Enterprise Capture

"Oracle has disclosed CVE-2026-61100, a critical (CVSS 9.8) flaw in Oracle WebCenter Enterprise Capture that lets an unauthenticated attacker take over the product over the network."

Oracle has disclosed CVE-2026-61100, a critical (CVSS 9.8) flaw in Oracle WebCenter Enterprise Capture that lets an unauthenticated attacker take over the product over the network.

What Is It

CVE-2026-61100 is a vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware, specifically in the Client Bundle component. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise the product. A successful attack can result in a complete takeover of Oracle WebCenter Enterprise Capture.

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting high impacts to confidentiality, integrity, and availability.

Why It Matters

The combination of network attack vector, low attack complexity, and no required privileges or user interaction means an attacker needs nothing more than HTTP access to a vulnerable instance. Because a successful attack yields full takeover of the product, with high confidentiality, integrity, and availability impact, exposed instances represent a serious risk to any environment running affected versions.

What's Vulnerable

Per Oracle, the affected supported versions are:

The vulnerable component is the Client Bundle within Oracle Fusion Middleware.

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running the affected versions should apply the fixes referenced in the Oracle Critical Patch Update Advisory (cpujul2026). This CVE does not appear in the supplied CISA KEV data, so there is no confirmation of active exploitation in the provided sources.

Sources