Junglewise Threat Intelligence

CVE-2026-35321: Oracle WebCenter Content improper access control in Content Server

CVE-2026-35321 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used for managing corporate documents and digital assets, contains a critical security vulnerability in its Content Server component. A user with low-level access to the system can exploit this flaw over the network to take full control of the application. This could lead to the theft of sensitive corporate data, unauthorized modification of documents, or a complete disruption of document management services.

Technical details

A vulnerability in the Content Server component of Oracle WebCenter Content (part of Oracle Fusion Middleware) is classified as Improper Access Control (CWE-284). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Due to a scope change (S:C), a successful exploit allows the attacker to not only compromise the WebCenter Content environment but potentially impact additional integrated products. The vulnerability results in a complete takeover of the affected component, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats