Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-60524: Oracle WebCenter Enterprise Capture Client Bundle Security Risk - Takeover Possible
CVE-2026-60524
CVE-2026-60524
Summary
Oracle WebCenter Enterprise Capture's client bundle in versions 12.2.1.4.0 and 14.1.2.0.0 is vulnerable to a serious security issue. This could allow an attacker to take control of the system, potentially affecting other connected products. We recommend updating to the latest version to protect your system.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| oracle corporation | oracle webcenter enterprise capture | 12.2.1.4.0 |
Original title
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily...
Original description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
mitre CVSS3.1
9.9
- https://www.oracle.com/security-alerts/cpujul2026.html vendor-advisory
Published: 21 Jul 2026 · Updated: 25 Jul 2026 · First seen: 24 Jul 2026