Executive brief
Oracle WebCenter Enterprise Capture, a tool used for digitizing and managing business documents, contains a critical security vulnerability in its Client Bundle component. An attacker with basic user credentials can exploit this over the network to take full control of the system. This could lead to the theft of sensitive documents, disruption of business operations, and potential unauthorized access to other connected corporate systems.
Technical details
A vulnerability exists in the Client Bundle component of Oracle WebCenter Enterprise Capture (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. The vulnerability is characterized by a scope change (CVSS S:C), meaning a successful exploit allows the attacker to move beyond the security scope of the affected component to impact other parts of the infrastructure. Successful exploitation results in a complete compromise of confidentiality, integrity, and availability (takeover of the application). The issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed