Cyber & AI intelligence
Wasteland.
Briefs indexed2663
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-83006 2026-09-15

CVE-2026-83006: Critical Scope-Changing Flaw in Oracle WebCenter Enterprise Capture

"Oracle has disclosed a CVSS 9.1 vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture that allows a network-based attacker to take over the product and impact adjacent systems."

Oracle has disclosed a CVSS 9.1 vulnerability in the Client Bundle component of Oracle WebCenter Enterprise Capture that allows a network-based attacker to take over the product and impact adjacent systems.

What Is It

CVE-2026-83006 is a vulnerability in the Oracle WebCenter Enterprise Capture product, part of Oracle Fusion Middleware, residing in the Client Bundle component. Oracle describes it as easily exploitable: an attacker with network access via HTTP and high privileges can compromise Oracle WebCenter Enterprise Capture, with no user interaction required.

The CVSS 3.1 base score is 9.1 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, network attack vector, low attack complexity, high privileges required, no user interaction, changed scope, and high impact to confidentiality, integrity, and availability. Exploitability subscore is 2.3; impact subscore is 6.0.

Why It Matters

Successful exploitation results in full takeover of Oracle WebCenter Enterprise Capture. The changed-scope flag is the important detail here: Oracle notes that while the vulnerability lives in WebCenter Enterprise Capture, attacks may significantly impact additional products. A compromise does not stay contained to the affected component; it becomes a pivot into the surrounding Fusion Middleware estate.

The high-privileges requirement is the only meaningful barrier. That constraint is weaker than it sounds in environments where middleware service accounts are broadly provisioned or where an attacker has already established a foothold.

No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation at this time.

What's Vulnerable

Per Oracle, the affected supported versions are:

The vulnerable component is the Client Bundle. No affected CPE entries were listed in the NVD record.

Patch Status

The CVE was published 2026-09-15 and carries an NVD status of Received, meaning NVD analysis is not yet complete. The sole reference is Oracle's security alert page for CSPU September 2026. No required-action deadline or CISA remediation guidance was supplied in the source material; administrators should consult the Oracle advisory for fixed versions and apply the corresponding update.

Sources