Junglewise Threat Intelligence

CVE-2026-35325: Oracle WebCenter Content access control vulnerability in Content Server

CVE-2026-35325 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content is a platform used by organizations to manage and share business documents and digital assets. A vulnerability in the Content Server component allows an attacker with basic user credentials to gain full control over the system via the network. This could lead to the unauthorized access, modification, or deletion of sensitive corporate documents and a total disruption of the content management service.

Technical details

This vulnerability is classified as Improper Access Control (CWE-284) within the Content Server component of Oracle WebCenter Content. It is easily exploitable by a low-privileged attacker who has network access via HTTP. The flaw does not require user interaction and has a high impact on confidentiality, integrity, and availability, effectively allowing for a total system takeover. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation details.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD record published

References

Related threats