Executive brief
Oracle WebCenter Enterprise Capture, a tool used for digitizing and processing business documents, contains a security flaw in its Client Bundle component. An attacker with basic user credentials can exploit this over the network to gain full control of the system. This could lead to the theft of sensitive documents, unauthorized modification of records, or a complete shutdown of the document capture service.
Technical details
A vulnerability exists in the Client Bundle component of Oracle WebCenter Enterprise Capture (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. While the specific vulnerability class (e.g., injection or insecure deserialization) is not explicitly detailed in the advisory, the impact is a complete compromise of Confidentiality, Integrity, and Availability (CIA triad). Successful exploitation allows for a total takeover of the affected product. Users should refer to the Oracle Critical Patch Update for remediation steps.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed: Initial advisory publication