Junglewise Threat Intelligence

CVE-2026-35323: Oracle WebCenter Content improper access control in Content Server

CVE-2026-35323 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle WebCenter Content, a platform used for managing corporate documents and digital assets. A user with low-level access can exploit this flaw over the network to take full control of the system. This could lead to the theft of sensitive business data, unauthorized modification of records, or a complete shutdown of the content management service.

Technical details

An improper access control vulnerability (CWE-284) exists in the Content Server component of Oracle WebCenter Content. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. A successful exploit results in a 'scope change' (S:C), meaning the attacker can move beyond the WebCenter Content environment to impact additional integrated products. This can lead to a total takeover of the affected system, compromising confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Security Alert published

References

Related threats