ZeroHour

CVE-2026-83003

niche

Authenticated SOAP Flaw in Oracle WebCenter Enterprise Capture Exposes Critical Data

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83003 is a high-severity vulnerability (CVSS 3.1 base score 8.5) in the Client Bundle component of Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is rated easily exploitable by a low-privileged, authenticated attacker with network access who sends crafted SOAP requests to the vulnerable service. Successful exploitation yields unauthorized read access to critical data — up to complete access to all data reachable through Enterprise Capture — plus unauthorized update, insert, and delete access to some of that data, and the scope change (S:C) indicates impacts can spread to additional products beyond Enterprise Capture itself. Organizations running the affected versions with SOAP endpoints reachable by low-trust accounts are at risk. No public proof of concept is known and the flaw is not in CISA's Known Exploited Vulnerabilities catalog, so exploitation in the wild is not known to be occurring.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83003 to all instances of WebCenter Enterprise Capture 12.2.1.4.0 and 14.1.2.0.0. Until patched, restrict network access to the Enterprise Capture SOAP interface to trusted users and network segments, and enforce least privilege on any accounts that can authenticate to it. Review audit logs for anomalous document read, update, insert, or delete activity, and inspect adjacent systems for signs of follow-on compromise given the confirmed scope change.

Affected
Oracle WebCenter Enterprise Capture (Oracle Fusion Middleware, component: Client Bundle)
Estimated exposure
nichelikely on the order of hundreds to low-thousands of internet-reachable deployments worldwide, with a larger but unknown internal/intranet footprint — WebCenter Enterprise Capture is niche enterprise document-capture middleware typically deployed inside corporate networks rather than on the public internet, and public scan data for Oracle WebCenter endpoints historically shows only small…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Enterprise Capture accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Enterprise Capture accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.