ZeroHour

CVE-2026-83339

moderate

Unauthenticated Takeover Flaw in Oracle WebCenter Enterprise Capture Client Bundle

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

Oracle WebCenter Enterprise Capture, a component of Oracle Fusion Middleware, contains an easily exploitable flaw in its Client Bundle that allows an unauthenticated attacker with network access via HTTP to compromise the application. Successful attacks can result in a complete takeover of the Enterprise Capture instance, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 9.8). Affected installations run versions 12.2.1.4.0 or 14.1.2.0.0. No public proof-of-concept or confirmed in-the-wild exploitation is known and the CVE is not on the CISA KEV list, but the unauthenticated, low-complexity network vector makes any internet-reachable deployment a high-value target.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83339 to all deployments of WebCenter Enterprise Capture 12.2.1.4.0 and 14.1.2.0.0. Until patched, restrict HTTP access to the Enterprise Capture client endpoints via VPN or IP allowlisting and monitor for unauthenticated or anomalous requests. Verify whether your Fusion Middleware estate includes WebCenter Enterprise Capture, as this niche component is often missed in WebLogic-focused patch reviews.

Affected
Oracle WebCenter Enterprise Capture (Oracle Fusion Middleware, component: Client Bundle)
Estimated exposure
moderate≈1,000s of enterprise deployments, with only a subset (likely hundreds) internet-exposed (estimate) — Enterprise Capture is an on-premises, enterprise-only document-capture module with no published install counts, and deployment patterns plus typical public scan results for WebCenter-family endpoints suggest low thousands of installations…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.