A critical vulnerability, CVE-2026-35285, has been identified in Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware. This vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. The flaw allows a low-privileged attacker with network access via T3 or IIOP protocols to compromise the system. Successful exploitation could result in full takeover of the affected product, with potential impact extending beyond the initial target due to scope changes. The CVSS score of 9.9 reflects the high severity and ease of exploitation. Organizations utilizing the affected versions of Oracle WebCenter Enterprise Capture or Oracle Fusion Middleware are strongly advised to apply the latest security patches provided by Oracle. Immediate action is recommended to mitigate the risk of unauthorized access and potential system compromise. Users should review Oracle's advisory for detailed mitigation steps and ensure all systems are updated to secure versions.