Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A flaw in the client bundle component of Oracle WebCenter Enterprise Capture permits a low‑privileged attacker with network access to the T3 and IIOP interfaces to gain unrestricted control over the application. The vulnerability results in full compromise of the system, affecting confidentiality, integrity, and availability. The weakness is an improper access control issue, identified as CWE-284.

Affected Systems

Affected systems include Oracle Corporation’s WebCenter Enterprise Capture, specifically version 12.2.1.4.0 and 14.1.2.0.0. These versions lack the fix for the client bundle flaw.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 reflects high severity, but the EPSS score of less than 1% indicates a low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Attackers need only network reachability to the T3 or IIOP interfaces and no elevated privileges to exploit the flaw.

Generated by OpenCVE AI on September 17, 2026 at 05:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle WebCenter Enterprise Capture to a patched version where the client bundle flaw is fixed.
  • Configure firewall or network segmentation to restrict inbound traffic on the T3 and IIOP interfaces to trusted hosts only.
  • If a patch is not yet available, disable the client bundle feature or block its URLs to prevent exploitation.

Generated by OpenCVE AI on September 17, 2026 at 05:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Client Bundle Access Control Vulnerability in Oracle WebCenter Enterprise Capture

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:27:35.124Z

Reserved: 2026-08-31T15:40:57.330Z

Link: CVE-2026-83008

cve-icon Vulnrichment

Updated: 2026-09-16T15:42:46.104Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:07.443

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83008

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T05:30:07Z

Weaknesses