Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle WebCenter Enterprise Capture executes to compromise Oracle WebCenter Enterprise Capture. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Enterprise Capture accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Enterprise Capture accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).
Published: 2026-09-15
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Modification and Integrity Compromise
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a local access control weakness in the client bundle of Oracle WebCenter Enterprise Capture. It allows a low‑privileged user who has logged on to the infrastructure to alter the behavior of the application, resulting in unauthorized creation, deletion, or modification of critical data. Because the flaw can be leveraged to gain complete access to all data exposed through the product, both confidentiality and integrity are severely impacted. The exploit requires user interaction from a person other than the attacker; therefore it is not remotely exploitable but can be triggered by an attacker who persuades a legitimate user to perform a specific action.

Affected Systems

The affected product is Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware, in versions 12.2.1.4.0 and 14.1.2.0.0. The client bundle component is the area affected; no other products have been identified as directly vulnerable, though successful exploitation may impact additional applications that rely on the same data.

Risk and Exploitability

The CVSS v3.1 base score of 7.2 indicates moderate to high severity with high confidentiality and integrity impact. The EPSS score is less than 1 percent, suggesting a very low exploitation probability at present. The vulnerability is not KEV catalog. Because the attack requires local user access and user interaction, the likelihood of widespread attacks is constrained, but the scope change shows that a successful compromise could undermine data integrity across the webcenter environment.

Generated by OpenCVE AI on September 17, 2026 at 05:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch for Oracle WebCenter Enterprise Capture 12.2.1.4.0 and 14.1.2.0.0 published by Oracle
  • Restrict client bundle access to only trusted users by enforcing least‑privilege on local accounts
  • Disable or remove unused client bundle features and, if possible, apply network segmentation to limit exposure to the webcenter components

Generated by OpenCVE AI on September 17, 2026 at 05:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Interaction‑Required Vulnerability in Oracle WebCenter Enterprise Capture Allows Unauthorized Data Modification

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle WebCenter Enterprise Capture executes to compromise Oracle WebCenter Enterprise Capture. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Enterprise Capture accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Enterprise Capture accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:27:57.580Z

Reserved: 2026-08-31T15:40:57.329Z

Link: CVE-2026-83004

cve-icon Vulnrichment

Updated: 2026-09-16T15:42:38.011Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:07.007

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83004

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T05:30:07Z

Weaknesses