Junglewise Threat Intelligence

CVE-2026-35324: Oracle WebCenter Content improper access control in Content Server

CVE-2026-35324 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content, a platform used by organizations to manage and share business documents, contains a security vulnerability in its Content Server component. An attacker with basic user credentials can exploit this flaw over the network to take full control of the system. This could lead to the unauthorized access, modification, or deletion of sensitive corporate data and a total disruption of document management services.

Technical details

A vulnerability in the Content Server component of Oracle WebCenter Content (part of Oracle Fusion Middleware) is classified as improper access control (CWE-284). The flaw is easily exploitable via HTTP by a low-privileged attacker with network access. Successful exploitation allows the attacker to compromise the confidentiality, integrity, and availability of the affected system, potentially leading to a complete takeover of the Oracle WebCenter Content instance. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle June 2026 Critical Patch Update published

References

Related threats