Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Enterprise Capture accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to critical data
Action: Patch Now
AI Analysis

Impact

Oracle WebCenter Enterprise Capture contains an easily exploitable weakness in its client bundle that allows an attacker who has only low privileges and network access via HTTP to compromise the system. Because the flaw bypasses normal access controls, compromised data can be read and, in some cases, the attacker may gain full read access to all data available through the application. The vulnerability is tied to Improper Access Control (CWE‑284) and results in a high confidentiality impact (CWE‑200).

Affected Systems

The flaw affects Oracle WebCenter Enterprise Capture, versions 12.2.1.4.0 and 14.1.2.0.0. The impact may extend beyond these specific installations, potentially affecting other Oracle Fusion Middleware components that rely on the same client bundle.

Risk and Exploitability

With a CVSS v3.1 base score of 7.7, the vulnerability is considered high severity. The EPSS score of less than 1% indicates that real‑world exploitation is currently unlikely, and the issue is not listed in CISA KEV. Nonetheless, an attacker can exploit the flaw remotely over HTTP without user interaction (no UI required) and requires only low privileges. The risk is compounded by the fact that successful exploitation can lead to confidentiality breaches that might cascade into other product instances.

Generated by OpenCVE AI on September 17, 2026 at 04:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for WebCenter Enterprise Capture 12.2.1.4.0 and 14.1.2.0.0 as described in the 2026 security advisory.
  • Limit HTTP access to the WebCenter Enterprise Capture instance to trusted networks and block unsolicited inbound traffic using firewalls or network segmentation.
  • Implement strict role‑based access controls on the WebCenter Enterprise Capture platform to ensure that low‑privileged accounts cannot read sensitive data.
  • Monitor logs for anomalous HTTP requests and review configuration settings regularly to verify the vulnerability has been fully remediated.

Generated by OpenCVE AI on September 17, 2026 at 04:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Data Exposure through Client Bundle Vulnerability in Oracle WebCenter Enterprise Capture
Weaknesses CWE-200

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Enterprise Capture accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:27:13.037Z

Reserved: 2026-08-31T15:40:57.330Z

Link: CVE-2026-83012

cve-icon Vulnrichment

Updated: 2026-09-16T15:54:48.399Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:07.910

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83012

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:45:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control