CVE-2026-83008
nicheLow-Privileged Takeover of Oracle WebCenter Enterprise Capture via T3/IIOP
Oracle WebCenter Enterprise Capture (Fusion Middleware, Client Bundle component) contains an easily exploitable vulnerability in versions 12.2.1.4.0 and 14.1.2.0.0 that allows a low-privileged attacker with network access via the T3 or IIOP protocols to fully compromise the product. Successful attacks can result in complete takeover, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.8). The T3/IIOP vector is characteristic of Oracle WebLogic-based deserialization flaws, which historically have been widely targeted once details circulate. Organizations running either affected version on network-reachable middleware ports are at risk from any authenticated or low-privilege foothold. As of now, the flaw is not in the CISA KEV catalog and no public proof-of-concept or observed exploitation is known.
What to do: Apply the Oracle Critical Patch Update that remediates this CVE to both 12.2.1.4.0 and 14.1.2.0.0 deployments as soon as the patch is available. Until patched, restrict or disable T3 and IIOP protocol access to WebLogic managed servers using network controls and WebLogic connection filters, allowing only trusted administration hosts. Review Enterprise Capture logs for unexpected client-bundle activity or account changes that could indicate compromise.
| Oracle WebCenter Enterprise Capture (Oracle Fusion Middleware, component: Client Bundle) | 12.2.1.4.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.