Junglewise Threat Intelligence

CVE-2026-35286: Oracle WebCenter Content authentication bypass in Content Server

CVE-2026-35286 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a critical security flaw in its Content Server component. An unauthorized person can use this vulnerability over the internet to take complete control of the system. This could lead to the theft of sensitive corporate data, unauthorized modification of documents, or a total shutdown of the document management service.

Technical details

This vulnerability is classified as a missing authentication for a critical function (CWE-306) within the Content Server component of Oracle WebCenter Content. It is remotely exploitable via HTTP without any prior authentication or user interaction. An attacker can leverage this flaw to gain full control over the affected instance, impacting the confidentiality, integrity, and availability of the entire system. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats