CVE-2026-35282: Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle)
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 9.9
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A critical remote code execution vulnerability affects Oracle WebCenter Enterprise Capture (Client Bundle component), versions 12.2.1.4.0 and 14.1.2.0.0. An attacker with a low-privilege account and network access via the T3 or IIOP protocols can reach the vulnerable service without any victim interaction, and the scope of impact extends beyond the directly compromised product. Successful exploitation results in full takeover of Oracle WebCenter Enterprise Capture, including complete loss of confidentiality, integrity, and availability. HarborGuard tracks this advisory and will make a patched-image rebuild available the moment Oracle publishes a fix.
HarborGuard Coverage
Detection for CVE-2026-35282 is available across every HarborGuard environment: the CVE is ingested from upstream Oracle and NVD feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle Oracle WebCenter Enterprise Capture Client Bundle artifacts.
AvailableHarborGuard surfaces this CVE with its CVSS 3.1 base score of 9.9 (Critical), weighted further against each environment's compliance policy to prioritize routing. Triage findings are dispatched to the inbox configured for the affected workload owner inside each customer organization.
AvailableNo fix version has been published by Oracle for this CVE. HarborGuard re-evaluates the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. For customers with auto-remediation enabled, the rebuild, regression-test run, and PR against affected workloads will follow without manual intervention.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the service over the network via the T3 or IIOP protocol; internet-exposed or internally network-accessible deployments are directly at risk.
- AuthenticationRequired
Any low-privilege account is sufficient; no administrative or elevated credentials are needed to trigger the vulnerability.
- Victim interactionNot required
No user action or social engineering is needed; the attacker can exploit the service directly without involving any other party.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and requires no special conditions, race timing, or environmental prerequisites.
Blast Radius
- Reads all data stored within Oracle WebCenter Enterprise Capture, including captured documents and associated metadata.
- Modifies or deletes persisted content, workflow configurations, and application data within the platform.
- Crashes or otherwise disables the Oracle WebCenter Enterprise Capture service, halting document capture operations.
- Because the CVSS scope is changed, adjacent or downstream products integrated with Oracle WebCenter Enterprise Capture can also be compromised through lateral movement.
How HarborGuard Handles This
Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-35282, the platform monitors the Oracle and NVD advisory feeds on every ingest cycle and will surface a patched-image rebuild the moment an upstream fix version is released. For customers with auto-remediation enabled, that rebuild will be followed immediately by a regression-test run and a PR opened against affected workloads, with no manual steps required. In the interim, compensating controls worth considering include restricting network-policy rules to block unauthenticated or unexpectedly sourced T3 and IIOP traffic to affected WebCenter nodes, applying egress filtering to limit lateral movement if a host is compromised, and reviewing whether the Client Bundle component can be feature-flag gated or disabled in environments where it is not actively used. Where compliance policy permits, HarborGuard can surface reachability context to help prioritize which running workloads are most exposed while the upstream fix is pending.
- Oracle Corporation / Oracle WebCenter Enterprise Capture12.2.1.4.0 · 14.1.2.0.0
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H