Executive brief
Oracle WebCenter Enterprise Capture is an enterprise document capture and processing platform used to digitize and manage critical business documents. A vulnerability in the Client Bundle component allows a low-privileged user with local system access to escalate privileges and gain unauthorized access to sensitive data across the system, potentially affecting multiple interconnected business applications and exposing confidential corporate information.
Technical details
This is a privilege escalation vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture. The vulnerability has high complexity (AC:H) and requires local system access (AV:L) with low user privileges (PR:L), but necessitates user interaction from a third party (UI:R). The attack has scope change implications, meaning successful exploitation can impact resources beyond the vulnerable component. Successful exploitation allows an attacker to create, delete, or modify critical data and access all data within WebCenter Enterprise Capture and potentially related systems. Affected versions are 12.2.1.4.0 and 14.1.2.0.0. Oracle has published security guidance but patch availability details are not specified in the available advisory information.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed