Executive brief
Oracle WebCenter Enterprise Capture is an enterprise document processing and capture solution used by large organizations to automate document workflows. A vulnerability in the Client Bundle component allows a low-privileged user with network access to escalate privileges and take complete control of the system, potentially compromising the confidentiality and integrity of captured documents and business-critical data.
Technical details
This is a privilege escalation vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture. The vulnerability is easily exploitable and allows a low-privileged attacker with network access via HTTP to escalate privileges and achieve complete system compromise. The attack requires authentication (PR:L) and no user interaction is required. Successful exploitation results in complete takeover including confidentiality, integrity, and availability impacts. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0; patch availability from Oracle should be verified against the September 2026 CPU release.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed