Junglewise Threat Intelligence

CVE-2026-35320: Oracle WebCenter Content access control bypass in Content Server

CVE-2026-35320 · Severity: critical · CVSS 9 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content is a platform used by organizations to manage and share business documents and digital assets. A critical vulnerability in the Content Server component allows an unauthenticated attacker to potentially take full control of the system over the network. Such an exploit could lead to the theft of sensitive corporate data, unauthorized modification of documents, or a complete shutdown of the content management service.

Technical details

This vulnerability (CWE-284) exists in the Content Server component of Oracle WebCenter Content. It is an improper access control flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. While the attack complexity is rated as high, a successful exploit results in a scope change (S:C), meaning the attacker can impact components beyond the immediate WebCenter Content environment. This can lead to a total loss of confidentiality, integrity, and availability (takeover) of the affected system. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Security Alert published

References

Related threats