Junglewise Threat Intelligence

CVE-2026-83006: Oracle WebCenter Enterprise Capture privilege escalation in Client Bundle

CVE-2026-83006 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Executive brief

Oracle WebCenter Enterprise Capture is a document capture and processing component used within Oracle's enterprise application suite. A critical vulnerability in the Client Bundle component allows high-privilege attackers to gain complete control of the system via network access, potentially compromising sensitive document data and business processes across connected enterprise applications.

Technical details

This is a privilege escalation vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture. The vulnerability is easily exploitable and requires only network access via HTTP and high-level privileges to attack. The vulnerability has a scope change (C in the CVSS vector), meaning successful exploitation can impact additional Oracle Fusion Middleware products beyond the directly vulnerable component. An attacker can achieve complete system takeover with impacts to confidentiality, integrity, and availability. No public exploit or active exploitation in the wild has been reported as of the advisory date.

Affected products

  • Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats