Executive brief
Oracle WebCenter Enterprise Capture, a tool used by businesses to digitize and process large volumes of documents, contains a security vulnerability in its Client Bundle component. An attacker with basic user access to the network can exploit this flaw to take full control of the system. This could lead to the theft of sensitive business documents, disruption of document processing workflows, and unauthorized access to integrated corporate data.
Technical details
A vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture (part of Oracle Fusion Middleware) allows for a complete system takeover. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation grants the attacker full control over the Confidentiality, Integrity, and Availability of the affected application. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. While specific CWE details were not provided in the advisory, the CVSS vector indicates a network-based attack with low complexity and no user interaction required.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle via the July 2026 Critical Patch Update
- 2026-07-21: advisory: NVD publication date