Junglewise Threat Intelligence

CVE-2026-35285: Oracle WebCenter Enterprise Capture access control bypass in Client Bundle

CVE-2026-35285 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Oracle WebCenter Enterprise Capture. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle WebCenter Enterprise Capture, a tool used for digitizing and processing business documents. A low-privileged user can exploit this flaw over the network to gain full control of the system. This could lead to the theft of sensitive documents, disruption of business operations, and potential unauthorized access to other connected corporate systems.

Technical details

This vulnerability (CWE-284) resides in the Client Bundle component of Oracle WebCenter Enterprise Capture. It is categorized as an improper access control issue that is easily exploitable over a network via the T3 or IIOP protocols. An attacker with low-level credentials can leverage this flaw to achieve a complete takeover of the application. Notably, the vulnerability includes a 'scope change' (S:C), meaning a successful exploit can impact security beyond the immediate WebCenter environment. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed: Initial advisory published by Oracle
  • 2026-06-17: advisory: NVD entry created

References

Related threats