Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-06-16
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Client Bundle component of Oracle WebCenter Enterprise Capture. An attacker who can reach the application over the network using the T3 or IIOP protocols can exploit this flaw without needing elevated privileges. The flaw enables the attacker to compromise the WebCenter Enterprise Capture server with complete authority, allowing execution of arbitrary code, disclosure of confidential data, alteration of system integrity, and denial of service. The weakness is consistent with an improper access control flaw that permits unauthorized management operations.

Affected Systems

Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These versions are part of Oracle Fusion Middleware and may be installed on enterprise server infrastructure.

Risk and Exploitability

The vulnerability has a CVSS 3.1 base score of 9.9, indicating critical impact across confidentiality, integrity, and availability. The EPSS score is below 1 %, suggesting that actual exploitation attempts are currently rare, but the attacker could still achieve a remote compromise due to the low effort required. The issue is not yet listed in the CISA KEV catalog, although its high severity warrants immediate attention. Attackers can reach the vulnerable component over the network, bypassing authentication and gaining full control of the target host and any connected Oracle services.

Generated by OpenCVE AI on June 17, 2026 at 17:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the patch released in the Oracle Security Alert for WebCenter Enterprise Capture to fix the client bundle flaw.
  • Upgrade to a non‑affected version or apply the latest available release of Oracle WebCenter Enterprise Capture.
  • Restrict traffic to the T3 and IIOP ports by configuring firewalls or network segmentation so that only trusted hosts can reach the application.
  • Disable unnecessary exposure of the client bundle and enforce strict role‑based access control so that only authorized administrators can perform privileged operations.
  • Enable logging and monitor for anomalous authentication or management activity, and review logs regularly for signs of exploitation attempts.

Generated by OpenCVE AI on June 17, 2026 at 17:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T13:49:21.483Z

Reserved: 2026-04-01T20:03:40.835Z

Link: CVE-2026-35280

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T06:30:03Z

Weaknesses

No weakness.