Junglewise Threat Intelligence

CVE-2026-35316: Oracle WebCenter Content improper access control in Content Server

CVE-2026-35316 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content is a platform used by organizations to manage and share business documents and digital assets. A critical vulnerability in the Content Server component allows an attacker with low-level user credentials to take full control of the system over the network. This could lead to the theft of sensitive corporate data, unauthorized modification of documents, and potential disruption of integrated business applications.

Technical details

This vulnerability (CWE-284) exists in the Content Server component of Oracle WebCenter Content. It is classified as an improper access control issue that is easily exploitable by a low-privileged attacker with network access via HTTP. The exploit results in a scope change (S:C), meaning a successful attack can impact other components or products beyond the immediate WebCenter Content environment. Successful exploitation grants the attacker full control over the confidentiality, integrity, and availability of the affected system. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle security alert published

References

Related threats