CVE-2026-60456

Oracle · WebCenter Enterprise Capture

A critical vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle allows an authenticated low privileged attacker to achieve full system takeover via network-based HTTP requests.

Executive summary

This critical vulnerability allows a low privileged attacker to achieve full system compromise of the Oracle WebCenter Enterprise Capture platform.

Vulnerability

This is an easily exploitable vulnerability within the Client Bundle component that permits an attacker with low privileges to execute unauthorized operations. The attack vector is network-based via HTTP, and the vulnerability supports scope change, potentially impacting the broader environment.

Business impact

The CVSS score of 9.9 underscores the severe potential for total system compromise. Successful exploitation results in full control over the application, leading to significant risks regarding data integrity and organizational security, especially given the scope change capabilities.

Remediation

Immediate Action: Apply the relevant security updates provided in the July 2026 Oracle Critical Patch Update for the affected software versions.

Proactive Monitoring: Monitor application logs for unusual administrative-level activity performed by accounts with lower privilege levels.

Compensating Controls: Utilize network security controls to restrict access to the WebCenter Enterprise Capture HTTP interface to trusted internal segments only.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

Organizations running the affected versions of Oracle WebCenter Enterprise Capture should treat this as a high-priority remediation item. Ensure that the latest security patches are applied in accordance with the July 2026 Oracle security advisory to prevent unauthorized access and potential system takeover.