CVE-2026-46778: Critical severity Oracle Oracle WebCenter Enterprise Capture vulnerability
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46778?
CVE-2026-46778 has a critical severity rating of 10.
Can CVE-2026-46778 be exploited remotely?
Yes, CVE-2026-46778 is easily exploitable by an unauthenticated attacker with network access via RMI.
Which versions of Oracle WebCenter Enterprise Capture are affected by CVE-2026-46778?
CVE-2026-46778 affects Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0.
What type of access does an attacker need to exploit CVE-2026-46778?
An attacker needs network access to exploit CVE-2026-46778.
How can organizations mitigate the risks of CVE-2026-46778?
Organizations should apply security patches or updates provided by Oracle for CVE-2026-46778.