CVE-2026-60445

Oracle · Oracle WebCenter Enterprise Capture

A vulnerability in Oracle WebCenter Enterprise Capture allows a low privileged network attacker to gain full system control via T3 or IIOP protocols.

Executive summary

An easily exploitable vulnerability in Oracle WebCenter Enterprise Capture (versions 12.2.1.4.0 and 14.1.2.0.0) allows low privileged attackers to compromise the application and achieve full system takeover.

Vulnerability

This is a remotely exploitable vulnerability occurring within the Client Bundle component, which allows an authenticated attacker with low privileges to leverage T3 or IIOP network access to fully compromise the software.

Business impact

The CVSS 3.1 base score of 9.9 underscores the critical danger this vulnerability presents. Successful exploitation enables an attacker to take complete control of the Enterprise Capture system, potentially compromising sensitive document workflows, scanned data, and integrated business processes.

Remediation

Immediate Action: Deploy the security patches provided in the July 2026 Oracle Critical Patch Update for the affected WebCenter Enterprise Capture versions.

Proactive Monitoring: Inspect network traffic for unauthorized T3 or IIOP connections and monitor application logs for signs of anomalous client activity.

Compensating Controls: If patching cannot be performed immediately, restrict access to the T3 and IIOP ports to only known, trusted administrative endpoints using network access control lists.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this flaw requires immediate attention to prevent unauthorized system takeover. Administrators must apply the recommended patches as soon as they become available to ensure the integrity and security of the Oracle WebCenter Enterprise Capture environment.