ZeroHour

CVE-2026-83005

niche

Low-Privilege Takeover Flaw in Oracle WebCenter Enterprise Capture

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83005 is a high-severity (CVSS 3.1: 8.8) vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware. It is described by Oracle as easily exploitable by a low-privileged (authenticated) attacker with network access via HTTP, and successful attacks can result in a complete takeover of the Oracle WebCenter Enterprise Capture installation, with high impact to confidentiality, integrity, and availability. Both supported releases are affected: versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so exploitation is not currently observed. Risk is concentrated in enterprise and government organizations running the affected releases, particularly where the capture service is reachable by large populations of low-privilege accounts over the network.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83005 to both affected tracks (12.2.1.4.0 and 14.1.2.0.0). Restrict HTTP access to the Enterprise Capture client and server to trusted networks and authenticated users, and review low-privileged Capture accounts for unnecessary access. Until patched, monitor for privilege escalation, configuration changes, or unusual activity by low-privilege accounts on Capture servers.

Affected
Oracle WebCenter Enterprise Capture (Oracle Fusion Middleware, Client Bundle component)12.2.1.4.0 and 14.1.2.0.0
Estimated exposure
nicheLikely low thousands of enterprise deployments worldwide, with an unknown and presumably small subset internet-exposed — WebCenter Enterprise Capture is an on-premises enterprise document-capture suite with no public active-install counts, typically deployed behind corporate networks for internal use, so exposure is limited to organizations running the two…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.