Junglewise Threat Intelligence

CVE-2026-35326: Oracle WebCenter Content improper access control in Content Server

CVE-2026-35326 · Severity: high · CVSS 7.2 · Published 2026-06-17

Technologies: Oracle Webcenter Content. Vendors: Oracle.

Executive brief

Oracle WebCenter Content is a platform used by organizations to manage and share business documents and digital assets. A vulnerability in the Content Server component allows a high-privileged user to gain full control over the system via the network. If exploited, an attacker could access sensitive corporate data, modify files, or disrupt document management operations.

Technical details

This vulnerability is classified as an improper access control issue (CWE-284) within the Content Server component of Oracle WebCenter Content. It is easily exploitable by a high-privileged attacker who has network access via HTTP. The flaw allows for a complete takeover of the affected Oracle WebCenter Content instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation details.

Affected products

  • Oracle WebCenter Content 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Security Alert published

References

Related threats