A critical vulnerability (CVE-2026-35283) has been identified in Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware. This vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. It allows a low-privileged attacker with network access via T3 or IIOP protocols to compromise the system, potentially leading to full takeover. While the vulnerability is specific to Oracle WebCenter Enterprise Capture, successful exploitation may impact additional products due to scope change. The CVSS score of 9.9 indicates a high severity level, emphasizing the urgency for mitigation. Organizations using the affected versions of Oracle Fusion Middleware should apply the latest security patches immediately. Until patched, administrators are advised to restrict network access to the vulnerable systems and monitor for suspicious activity. This vulnerability underscores the importance of timely patch management and network segmentation to prevent unauthorized access and potential system compromise.
CRITICAL
CVSS 9.9
CVE-2026-35283
2026-08-26
Critical Vulnerability in Oracle WebCenter Enterprise Capture (CVE-2026-35283)
A critical vulnerability (CVE-2026-35283) allows low-privileged attackers to take over Oracle WebCenter Enterprise Capture via network access. Affected versions include 12.2.1.4.0 and 14.1.2.0.0 of the Oracle Fusion Middleware platform.