Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-06-16
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an easy‑to‑exploit flaw in Oracle WebCenter Content’s Content Server component that allows an attacker with network access via HTTP to gain high‑privilege access and take complete control of the server. Successful exploitation yields full confidentiality, integrity, and availability compromise, enabling the attacker to read, modify, or delete data, install persistent backdoors, and potentially pivot to other applications through the scope‑changing nature of the flaw.

Affected Systems

Oracle WebCenter Content 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware, are affected. The flaw can also impact other products that operate in concert with WebCenter Content due to the scope change.

Risk and Exploitability

The CVSS 3.1 Base Score of 9.1 indicates critical severity, with low exploitation probability per an EPSS score of < 1% and no listing in CISA KEV. The likely attack vector is over the network via HTTP, requiring a high‑privilege attacker. Successful attacks can lead to a full takeover of the Content Server and potentially further compromise connected systems.

Generated by OpenCVE AI on June 17, 2026 at 20:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle WebCenter Content to the latest patched version that addresses CVE-2026-35270.
  • Restrict HTTP access to the Content Server to trusted IP ranges or VPN connections, and block exposure to the public internet.
  • Disable or restrict unused administrative interfaces and modules that are not required for normal operation.
  • Implement multi‑factor authentication for all privileged accounts and monitor logs for abnormal authentication or administrative activity.

Generated by OpenCVE AI on June 17, 2026 at 20:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T14:16:04.077Z

Reserved: 2026-04-01T20:03:40.835Z

Link: CVE-2026-35270

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T22:00:12Z

Weaknesses

No weakness.