Junglewise Threat Intelligence

CVE-2026-83008: Oracle WebCenter Enterprise Capture privilege escalation in Client Bundle

CVE-2026-83008 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Oracle WebCenter Enterprise Capture is a document capture and processing system used by enterprises to digitize paper workflows. A network-accessible vulnerability in the Client Bundle component allows a low-privileged user to escalate privileges and take over the entire system, potentially exposing or corrupting sensitive captured documents and business processes.

Technical details

The vulnerability is an easily exploitable flaw in the Oracle WebCenter Enterprise Capture Client Bundle component, affecting versions 12.2.1.4.0 and 14.1.2.0.0. A low-privileged attacker with network access can exploit the vulnerability via T3 or IIOP protocols to achieve complete system compromise (read, write, and execute). No user interaction or special authentication beyond basic network access is required. The attack results in full takeover of the affected system. Patch availability is unknown from the advisory text.

Affected products

  • Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats