Description
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The flaw resides in the Client Bundle of Oracle WebCenter Enterprise Capture and permits an unauthenticated attacker to gain complete control over the application. This results in total confidentiality, integrity, and availability loss, effectively enabling a full takeover. The weakness involves improper authentication checks, reflected in the CWE identifiers association.

Affected Systems

Oracle WebCenter Enterprise Capture 12.2.1.4.0 and 14.1.2.0.0 are impacted. These versions are part of the Oracle Fusion Middleware suite and normally handle media capture and storage services.

Risk and Exploitability

The CVSS 3.1 score of 9.8 signals critical severity, while the EPSS score of less than 1% indicates a low but non‑zero exploitation probability at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. With network access via HTTP and no authentication required, the attack vector is straightforward, allowing remote actors to exploit the flaw without any credential.

Generated by OpenCVE AI on September 18, 2026 at 15:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the Oracle update that resolves the Client Bundle authentication flaw or upgrade to a newer protected release of Oracle WebCenter Enterprise Capture.
  • Block or restrict inbound HTTP traffic untrusted networks, or enforce strict IP whitelisting to limit exposure.
  • Enable logging and alerting for authentication failures and unexpected access attempts, and monitor logs for indications of exploitation activity.

Generated by OpenCVE AI on September 18, 2026 at 15:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle WebCenter Enterprise Capture Client Bundle

Thu, 17 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle WebCenter Enterprise Capture Client Bundle

Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-306

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Enterprise Capture
CPEs cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Enterprise Capture
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Enterprise Capture
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T22:54:35.097Z

Reserved: 2026-08-31T15:40:57.353Z

Link: CVE-2026-83339

cve-icon Vulnrichment

Updated: 2026-09-15T22:44:47.011Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:47.243

Modified: 2026-09-21T18:06:46.613

Link: CVE-2026-83339

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T15:15:06Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function