Executive brief
Oracle WebCenter Enterprise Capture is a document capture and processing solution used in enterprise environments. A network-accessible vulnerability in the Client Bundle component allows a low-privileged user to gain full administrative control over the application, potentially exposing sensitive documents and disrupting document processing operations.
Technical details
This vulnerability is a privilege escalation issue in the Oracle WebCenter Enterprise Capture Client Bundle component affecting versions 12.2.1.4.0 and 14.1.2.0.0. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP and requires no user interaction. Successful exploitation results in complete compromise of the application with high impact to confidentiality, integrity, and availability. Patch availability is not explicitly mentioned in the provided advisory information.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed: CVE-2026-83009 published