Executive brief
Oracle WebCenter Enterprise Capture is a tool used by organizations to digitize and process large volumes of documents. A critical security flaw has been identified that allows an authorized user with low-level permissions to take complete control of the system over the network. This could lead to the theft of sensitive business documents, disruption of document processing workflows, and potential unauthorized access to other connected corporate systems.
Technical details
This vulnerability (CWE-284) exists in the Client Bundle component of Oracle WebCenter Enterprise Capture. It is classified as an improper access control issue that is easily exploitable via HTTP. An attacker with low-privileged credentials can leverage this flaw to gain full control over the application (Confidentiality, Integrity, and Availability impact). Notably, the vulnerability carries a 'Scope Change' (S:C) designation, indicating that a successful exploit can impact security components beyond the immediate Oracle WebCenter environment. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published