Summary
CVE-2026-60970 is a critical, unauthenticated remote compromise vulnerability affecting the Client Bundle subcomponent of Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware. The flaw is remotely exploitable over the network via the T3 and IIOP protocols without requiring any credentials or user interaction, and Oracle’s own advisory notes it may result in complete takeover of the affected product. It carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: The Client Bundle component of Oracle WebCenter Enterprise Capture exposes services over the T3 and IIOP protocols used by Oracle Fusion Middleware/WebLogic-based deployments; insufficient protection of these interfaces allows an attacker to interact with them without authentication.
- Trigger conditions: An attacker only needs network-layer access to the T3 or IIOP listener of a vulnerable Oracle WebCenter Enterprise Capture deployment — no valid credentials or prior access are required.
- Attack vector: Network (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: Successful exploitation can lead to full compromise of the Oracle WebCenter Enterprise Capture instance, with high impact to confidentiality, integrity, and availability (C:H/I:H/A:H) — consistent with complete system takeover.
Affected software
- Oracle WebCenter Enterprise Capture 12.2.1.4.0
- Oracle WebCenter Enterprise Capture 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided by Oracle in the August 2026 Critical Patch Update for all affected Oracle WebCenter Enterprise Capture deployments (versions 12.2.1.4.0 and 14.1.2.0.0). Oracle strongly recommends applying the patch as soon as possible, as it does not release fixes for previously reported issues outside its normal Critical Patch Update schedule except in exceptional circumstances.
- If immediate patching is not possible:
- Restrict network access to the T3 and IIOP listener ports/protocols on Oracle WebCenter Enterprise Capture servers to trusted internal hosts only; do not expose these interfaces to the internet.
- Use firewalls, network segmentation, or WebLogic connection filters to block or tightly control T3/IIOP traffic from untrusted networks.
- Monitor logs for anomalous T3/IIOP connection attempts as a compensating detective control until the patch can be applied.

