Summary
CVE-2026-60921 is a critical, easily exploitable vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture (part of Oracle Fusion Middleware). The flaw allows an unauthenticated attacker with network access via the T3 or IIOP protocols to fully compromise the affected system, impacting confidentiality, integrity, and availability. Oracle disclosed the issue as part of its August 2026 Critical Patch Update, and it carries the maximum practical severity rating of CVSS 9.8 (Critical).
Technical details
- Root cause: The vulnerability resides in the Client Bundle component of Oracle WebCenter Enterprise Capture, which exposes functionality over Oracle’s proprietary T3 and IIOP protocols (used by WebLogic-based Fusion Middleware deployments for RMI-style remote object communication).
- Trigger conditions: No authentication or user interaction is required. An attacker only needs network connectivity to the T3/IIOP listener of a vulnerable WebCenter Enterprise Capture instance.
- Attack vector: Network (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: Successful exploitation results in complete takeover of Oracle WebCenter Enterprise Capture, with high impact to confidentiality, integrity, and availability (C:H/I:H/A:H). Oracle’s advisory notes this as a "complete system takeover" scenario.
Affected software
- Oracle WebCenter Enterprise Capture 12.2.1.4.0
- Oracle WebCenter Enterprise Capture 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the patches provided in Oracle’s August 2026 Critical Patch Update for all affected Oracle WebCenter Enterprise Capture deployments (versions 12.2.1.4.0 and 14.1.2.0.0). Oracle strongly recommends applying these fixes as soon as possible due to the ease of exploitation and lack of authentication requirements.
- If immediate patching is not possible:
- Restrict network access to T3 and IIOP listener ports for WebCenter Enterprise Capture / WebLogic Server components to trusted internal hosts only; do not expose these ports to the internet.
- Use network segmentation and firewall rules to block untrusted inbound traffic to T3/IIOP endpoints.
- Monitor for anomalous T3/IIOP connection attempts or unexpected outbound connections from affected hosts, which may indicate exploitation attempts.
- Treat internet-facing WebCenter Enterprise Capture instances as high priority for emergency patching or temporary isolation until patched.

