Junglewise Threat Intelligence

CVE-2026-83012: Oracle WebCenter Enterprise Capture unauthorized data access in Client Bundle

CVE-2026-83012 · Severity: high · CVSS 7.7 · Published 2026-09-15

Executive brief

Oracle WebCenter Enterprise Capture is an enterprise document capture and processing system used for automating business workflows. A vulnerability in its Client Bundle component allows an attacker with low privileges and network access to bypass authorization controls and gain unauthorized access to sensitive business data, potentially exposing customer information and operational records stored within the system.

Technical details

This is an authorization/access control vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle component that allows low-privileged attackers with network access via HTTP to gain unauthorized access to critical data. The vulnerability requires authentication (PR:L indicates low privilege level required) but does not require user interaction. Successful exploitation results in high confidentiality impact with the ability to access all data available to the compromised WebCenter Enterprise Capture instance. The scope is changed (S:C), meaning an attacker can impact other Oracle Fusion Middleware products in the same deployment. No patch information is currently available in the advisory.

Affected products

  • Oracle WebCenter Enterprise Capture 12.2.1.4.0 and 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats