Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Client Bundle component of Oracle WebCenter Enterprise Capture allows an unauthenticated attacker to send crafted HTTP requests that bypass authentication and grant full control over the application. The weakness aligns with CWE‑306 Missing Authentication. Successful exploitation permits the attacker to read, modify, or delete critical data and disrupt the system, affecting confidentiality, integrity, and availability.

Affected Systems

Versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Enterprise Capture are affected. The product runs as part of Oracle Fusion Middleware and exposes an HTTP endpoint through its client bundle. It is inferred that deployments exposing this HTTP interface to the network are at risk; the data does not explicitly state whether the interface is exposed.

Risk and Exploitability

The CVSS 3.1 base score of 9.8 classifies the issue as Critical. The EPSS score is below 1%, indicating that widespread exploitation is unlikely currently. However, the vulnerability requires only unauthenticated HTTP traffic and no privileged access, making the attack path straightforward. The flaw is not listed in the CISA KEV catalog. The likely attack vector is unauthenticated HTTP traffic to the exposed service, inferred from the description that the issue is exploitable via the web interface.

Generated by OpenCVE AI on August 2, 2026 at 19:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an Oracle patch or upgrade to a version that fixes the authentication bypass in Oracle WebCenter Enterprise Capture.
  • Block or restrict inbound HTTP traffic to the application using firewalls, VPNs, or IP filtering so that only trusted hosts can reach the client bundle.
  • Review and enforce strict authentication and authorization controls to prevent unauthorized access to the client bundle service.

Generated by OpenCVE AI on August 2, 2026 at 19:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle WebCenter Enterprise Capture Client Bundle
Weaknesses CWE-287

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle WebCenter Enterprise Capture Client Bundle
Weaknesses CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:41:39.271Z

Reserved: 2026-07-08T15:51:55.613Z

Link: CVE-2026-61100

cve-icon Vulnrichment

Updated: 2026-07-23T19:41:35.123Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:00:12Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function