ZeroHour

CVE-2026-83012

niche

Authenticated Data Exposure in Oracle WebCenter Enterprise Capture Client Bundle

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83012 is an easily exploitable vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. A remote attacker who already holds a low-privileged account can trigger the flaw over HTTP to read data the attacker should not be entitled to, up to complete access to all data accessible through Oracle WebCenter Enterprise Capture. Because the CVSS vector indicates a scope change (S:C), successful attacks may also expose data in additional Oracle products beyond Enterprise Capture itself. The bug is confidentiality-only (C:H/I:N/A:N) with a CVSS 3.1 base score of 7.7 (high), and it does not currently appear in CISA's KEV catalog, with no public proof-of-concept known. Organizations running the affected on-premises Fusion Middleware releases should treat any internet-reachable or broadly shared Enterprise Capture deployment as exposed to credential-holding insiders or outsiders.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83012 to all WebCenter Enterprise Capture 12.2.1.4.0 and 14.1.2.0.0 installations, since in-place patching is the only vendor-supported fix. Restrict HTTP access to the Enterprise Capture client and server endpoints to trusted networks and VPN users, and audit low-privileged accounts for anomalous document-batch or repository reads. Because the scope change can spill into other Oracle products, review data accessible via the Capture service account beyond the Capture application itself.

Affected
Oracle WebCenter Enterprise Capture (Oracle Fusion Middleware, Client Bundle component)
Estimated exposure
nichelikely hundreds to low thousands of installations worldwide, mostly enterprise/government on-premises deployments — WebCenter Enterprise Capture is licensed enterprise ECM middleware typically deployed inside corporate networks rather than a mass-market product, so the exposed population is a small fraction of Oracle Fusion Middleware sites and very few…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Enterprise Capture accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.