Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-60524: Oracle WebCenter Enterprise Capture Client Bundle Security Risk - Takeover Possible

CVE-2026-60524 CVE-2026-60524
Summary

Oracle WebCenter Enterprise Capture's client bundle in versions 12.2.1.4.0 and 14.1.2.0.0 is vulnerable to a serious security issue. This could allow an attacker to take control of the system, potentially affecting other connected products. We recommend updating to the latest version to protect your system.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
oracle corporation oracle webcenter enterprise capture 12.2.1.4.0
Original title
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily...
Original description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
mitre CVSS3.1 9.9
Published: 21 Jul 2026 · Updated: 25 Jul 2026 · First seen: 24 Jul 2026