CVE-2026-60459: Critical severity Oracle Oracle WebCenter Enterprise Capture vulnerability
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60459?
The severity of CVE-2026-60459 is rated critical with a CVSS score of 9.9.
What versions of Oracle WebCenter Enterprise Capture are affected by CVE-2026-60459?
CVE-2026-60459 affects Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0.
What type of attackers can exploit CVE-2026-60459?
CVE-2026-60459 can be exploited by low privileged attackers with network access via HTTP.
How can organizations mitigate CVE-2026-60459?
Organizations should apply the latest security patches and updates from Oracle to mitigate CVE-2026-60459.
What is the potential impact of exploiting CVE-2026-60459?
Exploiting CVE-2026-60459 could lead to a complete compromise of Oracle WebCenter Enterprise Capture, affecting confidentiality, integrity, and availability.