Description
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-06-16
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle WebCenter Content, specifically its Content Server component, has a vulnerability that permits an unauthenticated attacker with network access via HTTP to execute arbitrary code. The flaw is difficult to exploit, but when successful it results in a full takeover of the WebCenter Content instance, compromising confidentiality, integrity, and availability of the application. The impact is a complete loss of control over the affected server.

Affected Systems

The affected products are Oracle WebCenter Content from Oracle Corporation, with the 12.2.1.4.0 and 14.1.2.0.0 release lines noted as vulnerable. The description also acknowledges that a scope change could potentially affect other Oracle products that interact with WebCenter Content, though the primary target remains the mentioned versions.

Risk and Exploitability

The CVSS v3.1 base score of 9.0 marks this vulnerability as Critical, with no authentication required, high complexity, no user interaction, and a changed scope, enabling attackers to fully compromise the system. The EPSS score is reported as less than 1%, indicating that the probability of exploitation at the time of this assessment is low, yet the severity remains high. Because the vulnerability is accessed over HTTP, it can be exploited remotely from any network location that can reach the WebCenter Content service, making it a significant threat to unpatched environments. The lack of a listing in CISA’s KEV catalog does not mitigate the risk, as the flaw remains publicly known and potentially exploitable.

Generated by OpenCVE AI on June 17, 2026 at 21:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch for CVE‑2026‑35320 as detailed in the Oracle security alert for June 2026.
  • If a patch is not immediately available, block external HTTP access to the WebCenter Content server, limiting connections to trusted internal networks only.
  • Deploy a Web Application Firewall or intrusion detection system on the WebCenter Content server to detect and block malicious HTTP requests targeting the vulnerable component.

Generated by OpenCVE AI on June 17, 2026 at 21:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Content
CPEs cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Content
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Content
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T15:36:44.624Z

Reserved: 2026-04-01T20:03:40.837Z

Link: CVE-2026-35320

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T22:45:03Z

Weaknesses

No weakness.