Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle WebCenter Enterprise Capture executes to compromise Oracle WebCenter Enterprise Capture. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 7.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.9 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Client Bundle of Oracle WebCenter Enterprise Capture permits an unauthenticated attacker who can reach the physical network segment attached to the hardware hosting the software to compromise the system. The vulnerability requires user interaction from a third party and has an attack complexity rated high. If exploited, it could lead to full takeover of the WebCenter Enterprise Capture application, compromising confidentiality, integrity and availability as reflected by a CVSS 3.1 score of 7.9.

Affected Systems

Oracle WebCenter Enterprise Capture products shipped as versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The issue is confined to the Client Bundle component of the Fusion Middleware stack.

Risk and Exploitability

The CVSS base score of 7.9 indicates a high level of risk, while the EPSS score of less than 1% suggests that attacks are infrequent but still possible. The vulnerability is not listed in the CISA KEV catalog, yet its scope change property means that compromise of the WebCenter application could extend to other components in the Fusion Middleware environment. Exploitation requires physical network access and a human who can interact with the target, reducing the likelihood of automated attacks but still presenting a significant threat to environments where such access is possible.

Generated by OpenCVE AI on September 17, 2026 at 04:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle WebCenter Enterprise Capture patches immediately once they become available; contact Oracle support to confirm the release schedule.
  • Segment the network to isolate the machine hosting WebCenter Enterprise Capture and block all non‑essential adjacent network traffic; enforce strict firewall rules that restrict access to the client bundle only from trusted hosts.
  • If the Client Bundle is not needed, disable or uninstall it to eliminate the attack surface and reduce potential impact.

Generated by OpenCVE AI on September 17, 2026 at 04:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title Adjacent Network Access Control Flaw in Oracle WebCenter Enterprise Capture
Weaknesses CWE-285

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle WebCenter Enterprise Capture executes to compromise Oracle WebCenter Enterprise Capture. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 7.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 7.9, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:26:26.630Z

Reserved: 2026-08-31T15:40:57.331Z

Link: CVE-2026-83022

cve-icon Vulnrichment

Updated: 2026-09-16T15:43:09.227Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:10.120

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83022

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:30:08Z

Weaknesses