Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Enterprise Capture accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Enterprise Capture accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-09-15
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Patch Now
AI Analysis

Impact

The vulnerability in Oracle WebCenter Enterprise Capture’s Client Bundle allows an attacker with low privileges who can reach the service over HTTP to compromise the application. Once exploited, the attacker can read critical data, and can also modify or delete data that the application exposes. The weakness is a low-privileged attacker with network reach via HTTP, enabling unauthorized read and write operations. The impact, as defined by the CVSS vector, shows severe confidentiality loss with moderate integrity damage and no availability impact.

Affected Systems

Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The product belongs to Oracle Fusion Middleware and is deployed in environments that expose the Client Bundle to HTTP traffic. No other product versions are disclosed as vulnerable in the current advisory.

Risk and Exploitability

The CVSS score of 8.5 places this issue in the high-severity range. Although the EPSS score is below 1%, indicating a low overall likelihood of public exploitation, the CVE is not listed in the KEV catalog. The flaw does not require authentication beyond user credentials presented over HTTP, making it easy to exploit once network access is available. Because the scope changes, successful exploitation could also impact other products that rely on or integrate with the compromised Enterprise Capture component.

Generated by OpenCVE AI on September 20, 2026 at 10:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in the security alert to address the Client Bundle vulnerability.
  • Restrict HTTP access to the WebCenter Enterprise Capture service to trusted internal networks and consider using a Web Application Firewall to block suspicious requests.
  • Continuously monitor audit logs for unauthorized data access or modification attempts and enforce strict role-based access controls to limit data exposure.

Generated by OpenCVE AI on September 20, 2026 at 10:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Attack Allows Unauthorized Data Access in Oracle WebCenter Enterprise Capture

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Enterprise Capture accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Enterprise Capture accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:27:40.568Z

Reserved: 2026-08-31T15:40:57.330Z

Link: CVE-2026-83007

cve-icon Vulnrichment

Updated: 2026-09-16T15:54:45.771Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:07.330

Modified: 2026-09-22T19:10:22.287

Link: CVE-2026-83007

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T11:00:09Z

Weaknesses