Executive brief
A critical vulnerability exists in Oracle WebCenter Enterprise Capture, a tool used for high-volume document scanning and processing. A low-privileged user can exploit this flaw to take full control of the system, potentially leading to the theft of sensitive documents or a complete shutdown of document processing operations. Because the vulnerability allows for a 'scope change,' an attacker could also use this as a foothold to compromise other connected business systems.
Technical details
This vulnerability (CWE-284) exists in the Client Bundle component of Oracle WebCenter Enterprise Capture. It is easily exploitable by a low-privileged attacker with network access via the T3 or IIOP protocols. The flaw is characterized by a CVSS 'Scope Change,' meaning a successful exploit allows the attacker to impact components beyond the immediate security scope of the WebCenter application. Successful exploitation results in a complete compromise of confidentiality, integrity, and availability (takeover) of the affected environment. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: Oracle Critical Patch Update published