Executive brief
Oracle WebCenter Enterprise Capture is an enterprise content capture and management system used to process and organize documents. A privilege escalation vulnerability in its Client Bundle allows an attacker with low-level network access to gain unauthorized access to sensitive data and modify or delete critical business records, potentially affecting other connected systems.
Technical details
The vulnerability is a privilege escalation flaw in the Client Bundle component of Oracle WebCenter Enterprise Capture. It requires low privileges and network access via HTTP, with no user interaction needed. An authenticated attacker can exploit this to read confidential data and perform unauthorized modifications or deletions. The vulnerability exhibits scope change, meaning the impact can extend beyond the affected product to other Oracle systems. Patches are available through Oracle's security bulletins.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed