Junglewise Threat Intelligence

CVE-2026-83022: Oracle WebCenter Enterprise Capture privilege escalation in Client Bundle

CVE-2026-83022 · Severity: high · CVSS 7.9 · Published 2026-09-15

Executive brief

Oracle WebCenter Enterprise Capture is an enterprise document capture and processing system used to digitize and automate paper-based workflows. A vulnerability in the Client Bundle component allows an unauthenticated attacker with access to the same physical network segment to compromise the system if a user clicks a malicious link or file, potentially enabling complete takeover of the capture system and lateral movement to other systems.

Technical details

This is a difficult-to-exploit vulnerability in Oracle WebCenter Enterprise Capture (versions 12.2.1.4.0 and 14.1.2.0.0) within the Client Bundle component. The attack requires an unauthenticated attacker to be on the same physical network segment and involves a combination of attack conditions: no authentication needed, but the user must interact with attacker-controlled content (UI:R) and a complex attack complexity (AC:H). Successful exploitation results in complete compromise of the affected system with impacts across confidentiality, integrity, and availability. The scope is marked as changed, meaning attacks on this product can impact other connected systems. No patch availability information is currently available in the advisory.

Affected products

  • Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats