Executive brief
Oracle WebCenter Enterprise Capture is a document processing and capture system used in enterprise workflows. An unauthenticated attacker on the network can exploit this vulnerability via HTTP to gain complete control of the system, including the ability to read, modify, or delete sensitive data and disrupt operations.
Technical details
This vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture allows unauthenticated remote code execution with no authentication or user interaction required. The flaw is easily exploitable and can be triggered over the network via HTTP. A successful attack results in complete compromise of the affected system with high impact to confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0; patch availability should be verified through Oracle's security advisories.
Affected products
- Oracle WebCenter Enterprise Capture 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed