Junglewise Threat Intelligence

CVE-2026-83005: Oracle WebCenter Enterprise Capture privilege escalation in Client Bundle

CVE-2026-83005 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Oracle WebCenter Enterprise Capture is an enterprise document processing and capture solution used by large organizations to automate document workflows. A vulnerability in the Client Bundle component allows a low-privileged user with network access to escalate privileges and take complete control of the system, potentially compromising the confidentiality and integrity of captured documents and business-critical data.

Technical details

This is a privilege escalation vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture. The vulnerability is easily exploitable and allows a low-privileged attacker with network access via HTTP to escalate privileges and achieve complete system compromise. The attack requires authentication (PR:L) and no user interaction is required. Successful exploitation results in complete takeover including confidentiality, integrity, and availability impacts. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0; patch availability from Oracle should be verified against the September 2026 CPU release.

Affected products

  • Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats