Junglewise Threat Intelligence

CVE-2026-35317: Oracle WebCenter Content access control bypass in Content Server

CVE-2026-35317 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content is a document management platform used by organizations to store and manage corporate records and digital assets. A vulnerability in the Content Server component allows an attacker with basic user credentials to gain full control over the system. This could lead to the unauthorized access, modification, or deletion of sensitive business documents and a total disruption of document management services.

Technical details

This vulnerability is classified as Improper Access Control (CWE-284) within the Content Server component of Oracle WebCenter Content. It is easily exploitable by a low-privileged attacker with network access via HTTP. The flaw allows for a complete compromise of the application, impacting confidentiality, integrity, and availability (total takeover). Affected versions include 12.2.1.4.0 and 14.1.2.0.0. While specific technical root causes are not detailed in the advisory, the CVSS vector indicates no user interaction is required and the attack complexity is low.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats