Executive brief
Oracle WebCenter Enterprise Capture is an enterprise document capture and processing system used for automating business workflows. A vulnerability in its Client Bundle component allows an attacker with low privileges and network access to bypass authorization controls and gain unauthorized access to sensitive business data, potentially exposing customer information and operational records stored within the system.
Technical details
This is an authorization/access control vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle component that allows low-privileged attackers with network access via HTTP to gain unauthorized access to critical data. The vulnerability requires authentication (PR:L indicates low privilege level required) but does not require user interaction. Successful exploitation results in high confidentiality impact with the ability to access all data available to the compromised WebCenter Enterprise Capture instance. The scope is changed (S:C), meaning an attacker can impact other Oracle Fusion Middleware products in the same deployment. No patch information is currently available in the advisory.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0 and 14.1.2.0.0
Timeline
- 2026-09-15: disclosed