CVE-2026-83005
nicheLow-Privilege Takeover Flaw in Oracle WebCenter Enterprise Capture
CVE-2026-83005 is a high-severity (CVSS 3.1: 8.8) vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware. It is described by Oracle as easily exploitable by a low-privileged (authenticated) attacker with network access via HTTP, and successful attacks can result in a complete takeover of the Oracle WebCenter Enterprise Capture installation, with high impact to confidentiality, integrity, and availability. Both supported releases are affected: versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so exploitation is not currently observed. Risk is concentrated in enterprise and government organizations running the affected releases, particularly where the capture service is reachable by large populations of low-privilege accounts over the network.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83005 to both affected tracks (12.2.1.4.0 and 14.1.2.0.0). Restrict HTTP access to the Enterprise Capture client and server to trusted networks and authenticated users, and review low-privileged Capture accounts for unnecessary access. Until patched, monitor for privilege escalation, configuration changes, or unusual activity by low-privilege accounts on Capture servers.
| Oracle WebCenter Enterprise Capture (Oracle Fusion Middleware, Client Bundle component) | 12.2.1.4.0 and 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.