Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-60916: Oracle WebCenter Enterprise Capture: Unauthorized Data Access and DOS

CVE-2026-60916 · published 16 days ago
Summary

The Oracle WebCenter Enterprise Capture product, used for document capture and management, has a vulnerability that allows unauthorized access to sensitive data and can cause partial system downtime. This affects specific versions of the software (12.2.1.4.0 and 14.1.2.0.0) and can be exploited by anyone with internet access. To protect your data and system, update to a secure version of the software as soon as possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
oracle corporation oracle webcenter enterprise capture 12.2.1.4.0
oracle webcenter_enterprise_capture 12.2.1.4.0
14.1.2.0.0
cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
Original advisory text
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily...
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Enterprise Capture accessible data as well as unauthorized read access to a subset of Oracle WebCenter Enterprise Capture accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L).
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published18 Aug 2026
Updated3 Sep 2026
First seen18 Aug 2026
Sources
CVE-2026-60916 · MITRE
Monitor software like this
Free during beta