Executive brief
Oracle WebCenter Enterprise Capture is an enterprise document capture and processing solution. A vulnerability in the Client Bundle component allows a high-privileged attacker to modify, delete, or access critical data through the web interface if a user interacts with a malicious request. The flaw can impact confidentiality and integrity of sensitive documents and data across the capture system.
Technical details
This is an authorization or request validation vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle component accessible via HTTP. The vulnerability requires high privilege (administrator or privileged user) on the attacker side, network reachability, and human interaction (social engineering or phishing) to trigger. A successful exploit results in unauthorized creation, deletion, or modification of critical data and unauthorized access to all data accessible within the WebCenter Enterprise Capture system. The scope changes from isolated to changed, indicating potential impact to other components or systems. Patches are likely available in Oracle's October 2026 or later security updates.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed: Published via NVD and Oracle security alert