ZeroHour

CVE-2026-83007

niche

Authenticated Data Compromise Flaw in Oracle WebCenter Enterprise Capture

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

A high-severity vulnerability (CVSS 3.1 base score 8.5) in the Client Bundle component of Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware, is easily exploitable by a low-privileged authenticated attacker with network access via HTTP. The flaw involves a scope change, meaning successful attacks on WebCenter Enterprise Capture can significantly impact additional products beyond the vulnerable component. A successful attacker gains unauthorized access to critical data or complete read access to all Oracle WebCenter Enterprise Capture accessible data, as well as unauthorized update, insert, or delete access to some of that data; availability is not impacted. Affected deployments are those running versions 12.2.1.4.0 or 14.1.2.0.0. The vulnerability is not on the CISA KEV list, no public proof-of-concept is known, and no exploitation in the wild has been reported.

What to do: Apply the Oracle Critical Patch Update (CPU) that fixes CVE-2026-83007 to WebCenter Enterprise Capture servers and any redistributed Client Bundle components on 12.2.1.4.0 or 14.1.2.0.0. Restrict HTTP access to Capture client and server endpoints to trusted users and networks, and review the privileges granted to low-privileged Capture accounts. Review audit logs for anomalous document reads or modifications by low-privilege users that could indicate attempted abuse.

Affected
Oracle WebCenter Enterprise Capture (Oracle Fusion Middleware, component: Client Bundle)
Estimated exposure
nichelikely on the order of a few thousand installations globally, mostly internal — WebCenter Enterprise Capture is a specialized enterprise document-capture product with no published install counts, and internet-wide scans typically find only a small number of exposed Oracle WebCenter endpoints, suggesting most…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Enterprise Capture accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Enterprise Capture accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.