CVE-2026-46778: Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. in Oracle Corporation Oracle WebCenter Enterprise Capture
CVE-2026-46778 is a critical vulnerability in Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0. It allows an unauthenticated attacker with network access via RMI to fully compromise the product. The vulnerability has a CVSS 3.1 base score of 10.0, indicating high impact on confidentiality, integrity, and availability. Exploitation can lead to complete takeover of Oracle WebCenter Enterprise Capture and may affect additional Oracle products. Oracle has released a Critical Security Patch Update advisory recommending prompt patching. No explicit patch versions are stated in the advisory content provided. Oracle strongly advises applying security patches without delay and suggests possible risk reduction by blocking network protocols required by the attack or restricting privileges until patches are applied.
AI Analysis
Technical Summary
This vulnerability affects Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware, specifically versions 12.2.1.4.0 and 14.1.2.0.0. It is an easily exploitable remote code execution vulnerability via RMI that requires no authentication and no user interaction. The vulnerability allows an attacker to take over the affected product, with a scope change potentially impacting other Oracle products. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, indicating network attack vector, low attack complexity, no privileges or user interaction required, and complete compromise of confidentiality, integrity, and availability. Oracle’s June 2026 Critical Security Patch Update advisory includes this vulnerability among 245 fixes and strongly recommends immediate patching. Until patches are applied, Oracle suggests mitigating risk by blocking required network protocols or removing unnecessary privileges, though these may impact functionality.
Potential Impact
Successful exploitation results in complete compromise of Oracle WebCenter Enterprise Capture, including full confidentiality, integrity, and availability impacts. The vulnerability is exploitable remotely without authentication, allowing attackers to take over the product. Additionally, the compromise may affect other Oracle products due to scope change. This represents a critical risk to organizations using the affected versions.
Mitigation Recommendations
Oracle strongly recommends applying the June 2026 Critical Security Patch Update as soon as possible to remediate this vulnerability. The vendor advisory does not specify exact patched versions for this issue but advises prompt patching of affected products. Until patches are applied, risk may be reduced by blocking network protocols required for the attack (such as RMI) and by removing unnecessary privileges or access to vulnerable components from users who do not need them. These mitigations may disrupt application functionality and are temporary measures. Patch status is not explicitly confirmed in the advisory; check Oracle’s official advisory for the latest remediation guidance.
CVE-2026-46778: Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. in Oracle Corporation Oracle WebCenter Enterprise Capture
Description
CVE-2026-46778 is a critical vulnerability in Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0. It allows an unauthenticated attacker with network access via RMI to fully compromise the product. The vulnerability has a CVSS 3.1 base score of 10.0, indicating high impact on confidentiality, integrity, and availability. Exploitation can lead to complete takeover of Oracle WebCenter Enterprise Capture and may affect additional Oracle products. Oracle has released a Critical Security Patch Update advisory recommending prompt patching. No explicit patch versions are stated in the advisory content provided. Oracle strongly advises applying security patches without delay and suggests possible risk reduction by blocking network protocols required by the attack or restricting privileges until patches are applied.
CVSS v3.1
Score 10.0critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability affects Oracle WebCenter Enterprise Capture component of Oracle Fusion Middleware, specifically versions 12.2.1.4.0 and 14.1.2.0.0. It is an easily exploitable remote code execution vulnerability via RMI that requires no authentication and no user interaction. The vulnerability allows an attacker to take over the affected product, with a scope change potentially impacting other Oracle products. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, indicating network attack vector, low attack complexity, no privileges or user interaction required, and complete compromise of confidentiality, integrity, and availability. Oracle’s June 2026 Critical Security Patch Update advisory includes this vulnerability among 245 fixes and strongly recommends immediate patching. Until patches are applied, Oracle suggests mitigating risk by blocking required network protocols or removing unnecessary privileges, though these may impact functionality.
Potential Impact
Successful exploitation results in complete compromise of Oracle WebCenter Enterprise Capture, including full confidentiality, integrity, and availability impacts. The vulnerability is exploitable remotely without authentication, allowing attackers to take over the product. Additionally, the compromise may affect other Oracle products due to scope change. This represents a critical risk to organizations using the affected versions.
Mitigation Recommendations
Oracle strongly recommends applying the June 2026 Critical Security Patch Update as soon as possible to remediate this vulnerability. The vendor advisory does not specify exact patched versions for this issue but advises prompt patching of affected products. Until patches are applied, risk may be reduced by blocking network protocols required for the attack (such as RMI) and by removing unnecessary privileges or access to vulnerable components from users who do not need them. These mitigations may disrupt application functionality and are temporary measures. Patch status is not explicitly confirmed in the advisory; check Oracle’s official advisory for the latest remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- oracle
- Date Reserved
- 2026-05-18T15:55:10.297Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://www.oracle.com/security-alerts/cspujun2026.html","vendor":"Oracle"}]
Threat ID: 6a31b60a0b89be68882657f3
Added to database: 06/16/2026, 20:46:02 UTC
Last enriched: 06/24/2026, 16:25:17 UTC
Last updated: 08/01/2026, 07:18:00 UTC
Views: 77
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.