Executive brief
Oracle WebCenter Enterprise Capture is a document capture and processing component used within Oracle's enterprise application suite. A critical vulnerability in the Client Bundle component allows high-privilege attackers to gain complete control of the system via network access, potentially compromising sensitive document data and business processes across connected enterprise applications.
Technical details
This is a privilege escalation vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture. The vulnerability is easily exploitable and requires only network access via HTTP and high-level privileges to attack. The vulnerability has a scope change (C in the CVSS vector), meaning successful exploitation can impact additional Oracle Fusion Middleware products beyond the directly vulnerable component. An attacker can achieve complete system takeover with impacts to confidentiality, integrity, and availability. No public exploit or active exploitation in the wild has been reported as of the advisory date.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed