CVE-2026-83009
nicheAuthenticated Takeover Flaw in Oracle WebCenter Enterprise Capture Client Bundle
CVE-2026-83009 is a high-severity (CVSS 8.8) vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware. It is easily exploitable by a low-privileged attacker who has network access to the product via HTTP — meaning the attacker needs a valid but unprivileged account rather than full credentials. Successful exploitation allows complete takeover of the Oracle WebCenter Enterprise Capture installation, with high impact on confidentiality, integrity, and availability. Affected supported versions are 12.2.1.4.0 and 14.1.2.0.0. No public proof of concept is known, the flaw is not on the CISA KEV list, and there is no indication of in-the-wild exploitation at this time.
What to do: Apply the Oracle Critical Patch Update that fixes CVE-2026-83009 to all WebCenter Enterprise Capture installations running 12.2.1.4.0 or 14.1.2.0.0. Until patched, restrict HTTP access to Enterprise Capture endpoints (especially the Client Bundle) to trusted networks/VPNs, audit and minimize low-privilege accounts, and review logs for unusual activity by those accounts.
| Oracle WebCenter Enterprise Capture (Oracle Fusion Middleware, Client Bundle component) | 12.2.1.4.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.