Junglewise Threat Intelligence

CVE-2026-35284: Oracle WebCenter Enterprise Capture access control bypass in Client Bundle

CVE-2026-35284 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Oracle WebCenter Enterprise Capture. Vendors: Oracle.

Executive brief

Oracle WebCenter Enterprise Capture, a tool used for digitizing and processing business documents, contains a critical security vulnerability. An attacker with basic user credentials can exploit this flaw over the network to take full control of the system. This could lead to the theft of sensitive business documents, disruption of document processing workflows, and potential unauthorized access to other connected corporate systems.

Technical details

This vulnerability is classified as Improper Access Control (CWE-284) within the Client Bundle component of Oracle WebCenter Enterprise Capture. It is exploitable by a low-privileged attacker with network access via the T3 or IIOP protocols. The flaw is characterized by a 'Scope Change' (S:C), meaning a successful exploit allows the attacker to move beyond the security boundaries of the affected component to impact other parts of the Oracle Fusion Middleware environment. Successful exploitation results in a complete loss of confidentiality, integrity, and availability (takeover). Affected versions include 12.2.1.4.0 and 14.1.2.0.0.

Affected products

  • Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References

Related threats