CVE-2026-60458

Oracle · WebCenter Enterprise Capture

A critical vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle allows an authenticated, low-privileged attacker to achieve full system compromise via T3 or IIOP protocols.

Executive summary

A critical vulnerability in Oracle WebCenter Enterprise Capture allows authenticated attackers to gain full control of the application and potentially impact surrounding systems.

Vulnerability

This is a remote code execution vulnerability involving the Client Bundle component. It requires an authenticated user with low privileges to send crafted requests over T3 or IIOP protocols to trigger the flaw.

Business impact

The vulnerability carries a CVSS score of 9.9, reflecting its potential for total system takeover. Because the exploit allows for a scope change, a successful attack could compromise not only the Capture application but also other integrated infrastructure, leading to severe data breaches and operational downtime.

Remediation

Immediate Action: Apply the latest Critical Patch Update provided by Oracle in their July 2026 security advisory to remediate this vulnerability.

Proactive Monitoring: Monitor network traffic for unusual T3 or IIOP protocol activity originating from low-privileged user accounts.

Compensating Controls: Restrict network access to the WebCenter Enterprise Capture server to known, trusted IP addresses and implement strict access controls on the T3 and IIOP service endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of this vulnerability and the potential for full system takeover, administrators should prioritize patching immediately. Ensure that the most recent security updates from Oracle are applied to all affected instances to eliminate this significant security risk.