Executive brief
Oracle WebCenter Enterprise Capture is a document capture and processing system used within enterprise environments. A vulnerability in the Client Bundle component allows a low-privileged network attacker to gain unauthorized access to sensitive data and modify critical information, potentially compromising the entire system and related systems connected to it.
Technical details
A privilege escalation vulnerability exists in the Client Bundle component of Oracle WebCenter Enterprise Capture due to improper access controls in the SOAP interface. The vulnerability allows a low-privileged attacker with network access to the SOAP endpoint to bypass authorization checks and access sensitive data. An authenticated user can exploit this weakness to read unauthorized data, modify records, or insert/delete information accessible through the WebCenter Enterprise Capture system. The scope is changed, indicating that successful exploitation may impact other connected Oracle Fusion Middleware components. Patches addressing this vulnerability are expected from Oracle's regular security update schedule.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed