Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Full system compromise
Action: Immediate Patch
AI Analysis

Impact

Vulnerability in Oracle WebCenter Enterprise Capture's Client Bundle permits a low‑privileged network attacker to bypass normal authentication controls and hijack the application. Successful exploitation results in full takeover of the WebCenter Enterprise Capture instance, exposing confidential data, modifying or deleting content, and potentially granting the attacker administrative privileges over the underlying system. The weakness is an authorization flaw (CWE‑284) affecting confidentiality, integrity, and availability.

Affected Systems

This issue affects Oracle Corporation's WebCenter Enterprise Capture product. The versions that are known to be vulnerable are 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is present in the Client Bundle component of these releases.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 signals high severity. The EPSS score is less than 1%, indicating limited current exploitation activity. The vulnerability is not listed in CISA's KEV catalog. The attack vector is request; a low‑privileged attacker with connectivity to the WebCenter server can trigger the flaw by sending a crafted request, making exploitation relatively straightforward for an adversary within the same network.

Generated by OpenCVE AI on September 17, 2026 at 04:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebCenter Enterprise Capture patch or upgrade to a fixed release as described 2026.
  • Restrict HTTP access to WebCenter Enterprise Capture servers to trusted IP addresses or VPN tunnels to limit exposure to potential attackers.
  • If a patch is not yet available, disable or remove the vulnerable Client Bundle component until remediation is applied, and monitor logs for suspicious access.

Generated by OpenCVE AI on September 17, 2026 at 04:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle WebCenter Enterprise Capture via HTTP

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:27:07.634Z

Reserved: 2026-08-31T15:40:57.330Z

Link: CVE-2026-83013

cve-icon Vulnrichment

Updated: 2026-09-16T15:42:54.916Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:08.047

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83013

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:45:17Z

Weaknesses