CVE-2026-83003
nicheAuthenticated SOAP Flaw in Oracle WebCenter Enterprise Capture Exposes Critical Data
CVE-2026-83003 is a high-severity vulnerability (CVSS 3.1 base score 8.5) in the Client Bundle component of Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is rated easily exploitable by a low-privileged, authenticated attacker with network access who sends crafted SOAP requests to the vulnerable service. Successful exploitation yields unauthorized read access to critical data — up to complete access to all data reachable through Enterprise Capture — plus unauthorized update, insert, and delete access to some of that data, and the scope change (S:C) indicates impacts can spread to additional products beyond Enterprise Capture itself. Organizations running the affected versions with SOAP endpoints reachable by low-trust accounts are at risk. No public proof of concept is known and the flaw is not in CISA's Known Exploited Vulnerabilities catalog, so exploitation in the wild is not known to be occurring.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83003 to all instances of WebCenter Enterprise Capture 12.2.1.4.0 and 14.1.2.0.0. Until patched, restrict network access to the Enterprise Capture SOAP interface to trusted users and network segments, and enforce least privilege on any accounts that can authenticate to it. Review audit logs for anomalous document read, update, insert, or delete activity, and inspect adjacent systems for signs of follow-on compromise given the confirmed scope change.
| Oracle WebCenter Enterprise Capture (Oracle Fusion Middleware, component: Client Bundle) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Enterprise Capture accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Enterprise Capture accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.