A critical remote code execution vulnerability (CVE-2026-46779) has been identified in Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware. This vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. The flaw allows a low-privileged attacker with network access via T3 protocol to compromise the system, potentially leading to full takeover. While the vulnerability is specific to Oracle WebCenter Enterprise Capture, exploitation may have cascading effects on other products due to scope changes. The CVSS 3.1 score of 9.9 indicates a high severity, with ease of exploitation and significant impact. Organizations using the affected versions should prioritize applying the latest security patches from Oracle. Mitigation measures include restricting network access to the vulnerable service, implementing proper firewall rules, and monitoring for unusual activity. Until a patch is applied, it is recommended to disable unnecessary services and ensure that only authorized users have access to the affected systems. This vulnerability underscores the importance of timely patch management and continuous security monitoring in enterprise environments.
CRITICAL
CVSS 9.9
CVE-2026-46779
2026-08-26
Critical Remote Code Execution Vulnerability in Oracle WebCenter Enterprise Capture (CVE-2026-46779)
A critical vulnerability (CVE-2026-46779) allows low-privileged attackers to take over Oracle WebCenter Enterprise Capture via network access. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Immediate patching is required to prevent exploitation.