Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-46778

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

View on NVD

Analysis

Esta vulnerabilidad crítica en Oracle WebCenter Enterprise Capture permite que un atacante remoto sin autenticación tome control total del sistema a través de RMI. Al afectar a componentes de Oracle Fusion Middleware, un ataque exitoso puede comprometer otros servicios e infraestructura conectada. Es vital actualizar de inmediato para prevenir el compromiso total del servidor y la exposición de datos sensibles.

Relevant roles

JavaBackendCyberSecurityCloud

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-306

EPSS

Probability of exploitation (next 30 days): 0.0045 (0.4%)
Percentile: 35.8%
EPSS: 2026-06-25

Affects

oracle:webcenter_enterprise_capture

Technical description

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

Published: 6/17/2026, 10:53:55 AM
Last modified: 6/26/2026, 3:40:35 AM

References

HomeEventsBlogResourcesTeam