ZeroHour

CVE-2026-83013

niche

Authenticated Takeover Flaw in Oracle WebCenter Enterprise Capture Client Bundle

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

Oracle WebCenter Enterprise Capture, a document capture component of Oracle Fusion Middleware, contains an easily exploitable vulnerability in its Client Bundle component that allows a low-privileged authenticated attacker with network access via HTTP to compromise the application. Successful exploitation results in a complete takeover of Oracle WebCenter Enterprise Capture, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.8). The affected versions are 12.2.1.4.0 and 14.1.2.0.0, both of which are supported releases commonly deployed in enterprise document management environments. Because exploitation requires only a low-privilege account (or any valid credentialed access), the risk is highest where many users can reach the capture interface. No public proof of concept is known and there is no evidence of in-the-wild exploitation to date.

What to do: Apply the Oracle Critical Patch Update (CPU) that addresses this CVE to both 12.2.1.4.0 and 14.1.2.0.0 deployments, and verify your installed version via the Middleware home or Enterprise Capture administration console. Restrict HTTP access to the Enterprise Capture client/server endpoints to trusted networks and VPN users only, and review audit logs for anomalous activity by low-privilege accounts. Since a takeover grants full control, rotate credentials and service accounts on affected hosts after patching if compromise is suspected.

Affected
Oracle WebCenter Enterprise Capture (Oracle Fusion Middleware, component: Client Bundle)12.2.1.4.0
Oracle WebCenter Enterprise Capture (Oracle Fusion Middleware, component: Client Bundle)14.1.2.0.0
Estimated exposure
nichelikely hundreds to a few thousand installations globally, mostly internal-facing — WebCenter Enterprise Capture is an enterprise-only ECM/middleware product typically deployed on internal corporate networks rather than internet-facing, and public scan data historically shows only hundreds to low thousands of exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.