Junglewise Threat Intelligence

CVE-2026-83004: Oracle WebCenter Enterprise Capture privilege escalation in Client Bundle

CVE-2026-83004 · Severity: high · CVSS 7.2 · Published 2026-09-15

Executive brief

Oracle WebCenter Enterprise Capture is an enterprise document capture and processing platform used to digitize and manage critical business documents. A vulnerability in the Client Bundle component allows a low-privileged user with local system access to escalate privileges and gain unauthorized access to sensitive data across the system, potentially affecting multiple interconnected business applications and exposing confidential corporate information.

Technical details

This is a privilege escalation vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture. The vulnerability has high complexity (AC:H) and requires local system access (AV:L) with low user privileges (PR:L), but necessitates user interaction from a third party (UI:R). The attack has scope change implications, meaning successful exploitation can impact resources beyond the vulnerable component. Successful exploitation allows an attacker to create, delete, or modify critical data and access all data within WebCenter Enterprise Capture and potentially related systems. Affected versions are 12.2.1.4.0 and 14.1.2.0.0. Oracle has published security guidance but patch availability details are not specified in the available advisory information.

Affected products

  • Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats