Executive brief
Oracle WebCenter Enterprise Capture is a tool used to digitize and process business documents. A critical security flaw in its Client Bundle component allows a user with low-level access to take full control of the system over the network. This could lead to the theft of sensitive documents, disruption of business operations, and potential unauthorized access to other connected corporate systems.
Technical details
A vulnerability classified as Improper Access Control (CWE-284) exists in the Client Bundle component of Oracle WebCenter Enterprise Capture. The flaw is easily exploitable by a low-privileged attacker with network access via the T3 protocol. Successful exploitation results in a scope change (S:C), meaning the attacker can potentially impact other products beyond the initial vulnerable component. This can lead to a complete takeover of the Oracle WebCenter Enterprise Capture environment, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory