Junglewise Threat Intelligence

CVE-2026-35283: Oracle WebCenter Enterprise Capture access control bypass in Client Bundle

CVE-2026-35283 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Oracle WebCenter Enterprise Capture. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle WebCenter Enterprise Capture, a tool used for high-volume document scanning and processing. A low-privileged user can exploit this flaw over the network to gain full control of the system. This could lead to the theft of sensitive documents, disruption of business operations, and potential unauthorized access to other connected corporate systems.

Technical details

This vulnerability (CWE-284) exists in the Client Bundle component of Oracle WebCenter Enterprise Capture. It is easily exploitable by a low-privileged attacker with network access via the T3 or IIOP protocols. The flaw allows for a scope change (S:C), meaning a successful exploit can impact not only the WebCenter application but also the underlying host or integrated products. Successful exploitation results in a complete compromise of confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats