CVE-2026-35285: Critical severity Oracle Oracle WebCenter Enterprise Capture vulnerability
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Oracle WebCenter Enterprise Capture (Client Bundle)from your environment.If the product or the Client Bundle is not required, uninstall or remove it from hosts to eliminate the vulnerable component.
- Configuration
Disable or stop T3 and IIOP listeners/protocols for the Client Bundle if they are not required, to remove the network attack vector described in the advisory.
Oracle WebCenter Enterprise Capture (Client Bundle) T3/IIOP listeners = disabled - Compensating control
Restrict or block T3 and IIOP network access to Oracle WebCenter Enterprise Capture servers at the network perimeter and internal firewalls/ACLs; allow access only from trusted management IPs.
- Compensating control
Segment and isolate Oracle WebCenter Enterprise Capture from other application and infrastructure networks (use VLANs, ACLs or host isolation) to limit scope and prevent lateral movement to other products.
- Operational
Increase monitoring and logging for signs of exploitation (unexpected T3/IIOP connections, unusual processes, or other anomalies); perform forensic investigation of affected hosts and rebuild systems if compromise is confirmed.
- Operational
If compromise is suspected or after remediation actions, rotate credentials, API keys, and certificates used by Oracle WebCenter Enterprise Capture and any integrated systems.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35285?
The severity of CVE-2026-35285 is critical with a CVSS score of 9.9.
How do I fix CVE-2026-35285?
To fix CVE-2026-35285, update Oracle WebCenter Enterprise Capture to the latest patched version provided by Oracle.
What are the affected versions for CVE-2026-35285?
The affected versions for CVE-2026-35285 are 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Enterprise Capture.
Who can exploit CVE-2026-35285?
CVE-2026-35285 can be exploited by a low privileged attacker with network access via T3 or IIOP.
What is the impact of CVE-2026-35285?
The impact of CVE-2026-35285 includes the potential for unauthorized access, modification, and disruption of services.