Junglewise Threat Intelligence

CVE-2026-35293: Oracle WebCenter Sites missing authentication for critical function

CVE-2026-35293 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites, a platform used for managing large-scale web content and customer experiences, contains a critical security flaw. An unauthorized person can remotely take full control of the system over the internet without needing a password. This could lead to a total loss of data confidentiality, unauthorized changes to website content, and service outages.

Technical details

A critical vulnerability exists in Oracle WebCenter Sites (component of Oracle Fusion Middleware) version 14.1.2.0.0. The flaw is classified as a missing authentication for a critical function (CWE-306), allowing an unauthenticated attacker to gain unauthorized access via the HTTP protocol. The vulnerability is easily exploitable and requires no user interaction. Successful exploitation results in a complete takeover of the affected WebCenter Sites instance, impacting confidentiality, integrity, and availability. Users should refer to the Oracle Critical Patch Update (CPU) for June 2026 for remediation steps.

Affected products

  • Oracle WebCenter Sites 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats