Junglewise Threat Intelligence

CVE-2026-35280: Oracle WebCenter Enterprise Capture access control bypass in Client Bundle

CVE-2026-35280 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Oracle WebCenter Enterprise Capture. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle WebCenter Enterprise Capture, a tool used for high-volume document scanning and processing. A low-privileged user can exploit this flaw to take full control of the system, potentially leading to the theft of sensitive documents or a complete shutdown of document processing operations. Because the vulnerability allows for a 'scope change,' an attacker could also use this as a foothold to compromise other connected business systems.

Technical details

This vulnerability (CWE-284) exists in the Client Bundle component of Oracle WebCenter Enterprise Capture. It is easily exploitable by a low-privileged attacker with network access via the T3 or IIOP protocols. The flaw is characterized by a CVSS 'Scope Change,' meaning a successful exploit allows the attacker to impact components beyond the immediate security scope of the WebCenter application. Successful exploitation results in a complete compromise of confidentiality, integrity, and availability (takeover) of the affected environment. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.

Affected products

  • Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References

Related threats