Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Application Takeover
Action: Apply Patch
AI Analysis

Impact

The flaw resides in the Client Bundle component of Oracle WebCenter Enterprise Capture and enables a low‑privileged attacker with network access through HTTP to execute arbitrary actions that result in a full takeover of the application. Successful exploitation removes confidentiality, integrity, and availability protections, giving the attacker control over the system.

Affected Systems

Oracle Corporation’s Oracle WebCenter Enterprise Capture product is impacted. The affected releases are 12.2.1.4.0 and 14.1.2.0.0, which are commonly deployed within Oracle Fusion Middleware environments.

Risk and Exploitability

The base CVSS score of 8.8 classifies this vulnerability as high severity with network access, low attack complexity, low privileges, and no user interaction required. The EPSS score of less than 1% indicates a low probability of exploitation at the the CISA KEV catalog. Because the attack can be carried out by an attacker who only needs HTTP access and does not require elevated credentials, the potential impact is substantial if the affected environment is exposed to untrusted networks.

Generated by OpenCVE AI on September 17, 2026 at 04:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact Oracle to identify and deploy the security patch that addresses this issue.
  • Configure network firewalls or load balancers to restrict HTTP access to Oracle WebCenter Enterprise Capture only to trusted IP ranges or internal hosts.
  • Enable and review audit logging for authentication and access events exploitation attempts.

Generated by OpenCVE AI on September 17, 2026 at 04:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Remote Takeover of Oracle WebCenter Enterprise Capture via HTTP

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:27:52.116Z

Reserved: 2026-08-31T15:40:57.329Z

Link: CVE-2026-83005

cve-icon Vulnrichment

Updated: 2026-09-16T15:42:40.962Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:07.117

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83005

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:45:17Z

Weaknesses