Junglewise Threat Intelligence

CVE-2026-35270: Oracle WebCenter Content improper access control in Content Server

CVE-2026-35270 · Severity: critical · CVSS 9.1 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, contains a critical vulnerability in its Content Server component. A high-privileged attacker can exploit this flaw over the network to gain full control of the system. Because this component often integrates with other business applications, a successful attack could also compromise additional connected systems and data.

Technical details

A vulnerability classified as Improper Access Control (CWE-284) exists in the Content Server component of Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0. The flaw is easily exploitable by a high-privileged attacker with network access via HTTP. The vulnerability is notable for a 'scope change' (S:C), meaning an exploit can impact resources beyond the security scope of the WebCenter Content environment. Successful exploitation allows for a complete takeover of the affected product. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed: Initial advisory publication by Oracle and NVD.

References

Related threats