Executive brief
Oracle WebCenter Enterprise Capture, a tool used for digitizing and processing large volumes of business documents, contains a high-severity vulnerability in its Client Bundle component. An unauthenticated attacker could exploit this flaw over the network to gain full control of the system. This could lead to the theft of sensitive business documents, data corruption, or a complete shutdown of document processing operations.
Technical details
A vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture (part of Oracle Fusion Middleware) allows for a complete system takeover. The flaw is exploitable by an unauthenticated attacker via HTTP over a network. While the attack complexity is rated as high, a successful exploit results in a total loss of confidentiality, integrity, and availability (impact score of 6.0 for each). Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD record published