CVE-2026-46781: Critical severity Oracle Oracle WebCenter Enterprise Capture vulnerability
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable or otherwise stop exposing RMI network access for Oracle WebCenter Enterprise Capture instances (applicable to affected versions 12.2.1.4.0 and 14.1.2.0.0) to prevent unauthenticated remote compromise.
Oracle WebCenter Enterprise Capture (Client Bundle) RMI network access = disabled - Compensating control
Restrict network access to RMI on hosts running Oracle WebCenter Enterprise Capture (affected versions 12.2.1.4.0 and 14.1.2.0.0) using perimeter and host firewalls or ACLs; allow only trusted management IPs or internal networks.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46781?
CVE-2026-46781 has a critical severity rating of 10.
How do I fix CVE-2026-46781?
To fix CVE-2026-46781, apply the latest security patch provided by Oracle for the affected versions.
What versions are affected by CVE-2026-46781?
The affected versions for CVE-2026-46781 are 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Enterprise Capture.
What type of vulnerability is CVE-2026-46781?
CVE-2026-46781 is an easily exploitable vulnerability that allows unauthenticated attackers with network access to compromise Oracle WebCenter Enterprise Capture.
What impact does CVE-2026-46781 have?
CVE-2026-46781 can lead to complete compromise of the confidentiality, integrity, and availability of affected systems.