CVE-2026-83010
nicheHigh-Privilege, User-Interaction Data Compromise in Oracle WebCenter Enterprise Capture
Oracle WebCenter Enterprise Capture (Fusion Middleware, Client Bundle component) versions 12.2.1.4.0 and 14.1.2.0.0 contain an easily exploitable flaw reachable over HTTP by a network attacker who already holds high privileges. Exploitation requires interaction from a person other than the attacker, meaning victims are likely induced (e.g., via social engineering) to take an action that triggers the malicious request from their authenticated session. A successful attack can grant unauthorized creation, deletion, or modification of critical data, or full read access to all data accessible to WebCenter Enterprise Capture, and because of a scope change, the impact can extend to additional products beyond Enterprise Capture itself. Organizations running either affected version in their Fusion Middleware stack are exposed, though the high privilege requirement narrows the attacker pool to insiders or already-compromised privileged accounts. No public proof-of-concept exists and the vulnerability is not listed in CISA's KEV catalog, so exploitation in the wild is not currently observed.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83010 to all WebCenter Enterprise Capture installations running 12.2.1.4.0 or 14.1.2.0.0 (the data does not specify a fixed version, so follow Oracle's CPU advisory for the remediating release). Restrict HTTP access to Enterprise Capture to trusted networks and limit high-privilege accounts, and train privileged users to be wary of requests that could trigger the required victim interaction. Review audit logs on affected systems for unexplained data creation, deletion, or modification and for cross-product data access consistent with the scope-change impact.
| Oracle WebCenter Enterprise Capture (Oracle Fusion Middleware, Client Bundle component) | 12.2.1.4.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Enterprise Capture accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Enterprise Capture accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.