CVE-2026-35323

Oracle · WebCenter Content

A critical vulnerability in Oracle WebCenter Content allows a low-privileged attacker to achieve full system takeover via network-based HTTP exploitation.

Executive summary

A critical vulnerability in Oracle WebCenter Content permits unauthorized remote takeover of the application by low-privileged attackers, posing a severe risk to organizational data integrity.

Vulnerability

This vulnerability resides in the Content Server component and allows a low-privileged authenticated attacker to compromise the application over the network. The flaw is easily exploitable and does not require complex user interaction.

Business impact

The CVSS score of 9.9 reflects the extreme severity of this flaw, which allows for complete compromise of the system. Because this vulnerability affects the Content Server, it could result in the unauthorized disclosure or manipulation of critical business documents, leading to significant reputational and operational damage.

Remediation

Immediate Action: Apply the vendor-recommended updates for Oracle WebCenter Content available at https://www.oracle.com/security-alerts/cspujun2026.html.

Proactive Monitoring: Monitor server logs for unusual administrative activities or unauthorized modifications to content repositories.

Compensating Controls: Utilize a WAF to filter traffic and restrict access to the Content Server to authorized network segments only.

Exploitation status

Public Exploit Available: false

Analyst recommendation

This vulnerability presents a severe risk to the confidentiality and integrity of your business assets. Organizations should prioritize patching these affected versions immediately to prevent potential exploitation.