CVE-2026-60447

Oracle · WebCenter Enterprise Capture

A critical vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle allows an authenticated low privileged attacker to achieve full system takeover via network-based HTTP requests.

Executive summary

This critical vulnerability allows a low privileged attacker to achieve full system compromise of the Oracle WebCenter Enterprise Capture platform.

Vulnerability

This is an easily exploitable vulnerability within the Client Bundle component that permits an attacker with low privileges to execute unauthorized operations. The attack vector is network-based via HTTP, and the vulnerability supports scope change, potentially impacting the broader environment.

Business impact

The CVSS score of 9.9 reflects the extreme severity of this flaw, which enables complete system takeover. Successful exploitation leads to a total loss of confidentiality, integrity, and availability for the affected Oracle instance, creating significant risk for data exposure and operational disruption.

Remediation

Immediate Action: Review the July 2026 Oracle Critical Patch Update advisory and apply the specific security patches for versions 12.2.1.4.0 and 14.1.2.0.0.

Proactive Monitoring: Inspect web server access logs for anomalous HTTP requests originating from low privileged user accounts that attempt to access restricted Client Bundle functionality.

Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall to filter malicious traffic patterns targeting the WebCenter Enterprise Capture interface.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

Given the critical nature of this vulnerability and the potential for full system takeover, organizations must prioritize patching these Oracle WebCenter instances. Coordinate with your database and middleware administrators to test and deploy the vendor-supplied patches immediately to minimize the window of exposure.