CVE-2026-83006
nicheHigh-Privilege Takeover Flaw in Oracle WebCenter Enterprise Capture Client Bundle
CVE-2026-83006 is a critical (CVSS 9.1) vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is easily exploitable by a high-privileged attacker who has network access to the product via HTTP, requiring no user interaction. Successful exploitation results in a complete takeover of Oracle WebCenter Enterprise Capture with high impact to confidentiality, integrity, and availability, and due to a scope change the attack may also significantly impact additional products beyond the vulnerable component. Organizations running either affected version in their capture workflows are exposed, though the high-privilege prerequisite limits the attacker pool to compromised or malicious privileged accounts. No public proof of concept is known and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, indicating no observed in-the-wild exploitation to date.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83006 to both 12.2.1.4.0 and 14.1.2.0.0 deployments, prioritizing any instance reachable over HTTP. Until patched, restrict network access to Enterprise Capture client endpoints and audit privileged accounts for anomalous activity, since exploitation requires high privileges and could cascade to other products via the scope change.
| Oracle WebCenter Enterprise Capture (Fusion Middleware, Client Bundle component) | 12.2.1.4.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.