Junglewise Threat Intelligence

CVE-2026-35295: Oracle WebCenter Sites authentication bypass in WebCenter Sites component

CVE-2026-35295 · Severity: high · CVSS 7.5 · Published 2026-06-17

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites, a platform used for managing large-scale web content and digital experiences, contains a security vulnerability that could allow an unauthorized user to take full control of the system. An attacker with low-level access to the network could exploit this flaw to access sensitive data, modify website content, or disrupt operations. While the attack is complex to execute, a successful breach results in a total compromise of the affected site's confidentiality and integrity.

Technical details

A vulnerability classified as Missing Authentication for Critical Function (CWE-306) exists in the WebCenter Sites component of Oracle Fusion Middleware. The flaw allows a low-privileged attacker to perform unauthorized actions via HTTP. Although the attack complexity is rated as high, suggesting specific timing or environmental conditions are required, a successful exploit enables a complete takeover of the product (impacting Confidentiality, Integrity, and Availability). Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle June 2026 Critical Patch Update for remediation steps.

Affected products

  • Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD publication date

References

Related threats