ZeroHour

CVE-2026-83022

niche

Unauthenticated Adjacent-Network Takeover in Oracle WebCenter Enterprise Capture

CVSS 3.1
7.9 high
EPSS
Published
()
Modified
AI analysis

A difficult-to-exploit, unauthenticated vulnerability exists in the Client Bundle component of Oracle WebCenter Enterprise Capture (part of Oracle Fusion Middleware), affecting versions 12.2.1.4.0 and 14.1.2.0.0. To exploit it, an attacker must be on the same physical communication segment as the server hosting Enterprise Capture and must rely on interaction from a person other than the attacker (e.g., a user being tricked into an action), which makes remote opportunistic abuse unlikely. Successful attacks result in a complete takeover of Oracle WebCenter Enterprise Capture with high impact to confidentiality, integrity, and availability, and because of a scope change the impact can extend to additional products beyond Enterprise Capture itself (CVSS 3.1 base score 7.9). Organizations running the affected Fusion Middleware versions in document-capture workflows are the impacted population. No public proof of concept is known, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83022 to all WebCenter Enterprise Capture 12.2.1.4.0 and 14.1.2.0.0 installations as soon as it is released. Until patched, segment the network and use host firewalls to restrict which clients can reach Enterprise Capture client-server communication ports, and treat users on those segments as untrusted given the UI:R requirement. Review Enterprise Capture logs for anomalous client-bundle sessions or unexpected administrative activity following any suspicious user interaction.

Affected
Oracle WebCenter Enterprise Capture (Oracle Fusion Middleware, component: Client Bundle)
Estimated exposure
nichelikely hundreds to low thousands of enterprise deployments worldwide (no public install counts) — WebCenter Enterprise Capture is a niche enterprise document-capture product deployed mainly inside corporate and government networks, and the adjacent-network (AV:A) requirement further shrinks the practically attackable set; no public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle WebCenter Enterprise Capture executes to compromise Oracle WebCenter Enterprise Capture. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 7.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.