Junglewise Threat Intelligence

CVE-2026-35296: Oracle WebCenter Sites authentication bypass and system takeover

CVE-2026-35296 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites, a platform used for managing large-scale web content and digital experiences, contains a critical security flaw. An unauthorized person can remotely take full control of the system over the internet without needing a username or password. This could lead to the complete theft of sensitive data, modification of website content, or a total shutdown of the service.

Technical details

A critical vulnerability exists in the WebCenter Sites component of Oracle Fusion Middleware, specifically affecting versions 12.2.1.4.0 and 14.1.2.0.0. The flaw is categorized as a missing authentication for a critical function (CWE-306), allowing an unauthenticated attacker with network access via HTTP to bypass security controls. This is an easily exploitable vulnerability that requires no user interaction. Successful exploitation results in a complete takeover of the Oracle WebCenter Sites instance, impacting confidentiality, integrity, and availability. Oracle has addressed this in their June 2026 security alerts.

Affected products

  • Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats