Junglewise Threat Intelligence

CVE-2026-46778: Oracle WebCenter Enterprise Capture auth bypass in Client Bundle

CVE-2026-46778 · Severity: critical · CVSS 10 · Published 2026-06-17

Technologies: Oracle WebCenter Enterprise Capture. Vendors: Oracle.

Executive brief

Oracle WebCenter Enterprise Capture, a tool used for digitizing and processing business documents, contains a critical security flaw. An unauthorized person can remotely take full control of the system over the network without needing a username or password. This could lead to the theft of sensitive documents, a total shutdown of document processing operations, or the use of the system to attack other parts of the corporate network.

Technical details

A vulnerability classified as Missing Authentication for Critical Function (CWE-306) exists in the Client Bundle component of Oracle WebCenter Enterprise Capture. The flaw is accessible via Remote Method Invocation (RMI) over a network. An unauthenticated attacker can exploit this to gain full control over the affected instance. Due to a scope change (Status: Changed), an exploit may also allow the attacker to impact additional products beyond the initial target. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: advisory: Oracle published the vulnerability details in the June 2026 security alert.
  • 2026-06-17: disclosed

References

Related threats