Summary
CVE-2026-60958 is a critical vulnerability in the Client Bundle subcomponent of Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware. The flaw allows a completely unauthenticated attacker with network access via HTTP to compromise the application, with a realistic potential for full takeover of the affected system. Oracle rates this issue 9.8 (Critical) on the CVSS v3.1 scale, reflecting the absence of any authentication or user-interaction requirements combined with high impact to confidentiality, integrity, and availability.
Technical details
- Root cause: A weakness in the Client Bundle subcomponent of Oracle WebCenter Enterprise Capture that can be triggered over the HTTP interface exposed by the application.
- Trigger conditions: No authentication, privileges, or user interaction are required to exploit the vulnerability; the attacker only needs network reachability to the vulnerable HTTP service.
- Attack vector: Network (remote), low attack complexity — Oracle classifies this as "easily exploitable."
- Impact: Successful exploitation can result in complete compromise of Oracle WebCenter Enterprise Capture, with high impact to confidentiality, integrity, and availability, and the potential for full application/system takeover.
Affected software
- Oracle WebCenter Enterprise Capture 12.2.1.4.0
- Oracle WebCenter Enterprise Capture 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Security Patch Update for Oracle WebCenter Enterprise Capture addressing CVE-2026-60958 for affected versions 12.2.1.4.0 and 14.1.2.0.0. Oracle strongly recommends applying the security patches as soon as possible.
- If patching cannot be performed immediately: Restrict network access to Oracle WebCenter Enterprise Capture’s HTTP interface to trusted internal networks only, and place the application behind a firewall or VPN so it is not reachable from the public internet. These are interim compensating controls only — the vendor patch remains the required fix.

