CVE-2026-35270: Critical severity Oracle Oracle WebCenter Content vulnerability
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to Oracle WebCenter Content HTTP ports to trusted IPs using firewall rules, network ACLs, or a WAF; block HTTP access from untrusted networks (including the internet) and isolate affected instances until an official vendor fix is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35270?
CVE-2026-35270 has a severity rating of 9.1, indicating it is critical.
How do I fix CVE-2026-35270?
To mitigate CVE-2026-35270, apply the latest security patch provided by Oracle for the affected versions.
What versions are affected by CVE-2026-35270?
The affected versions of Oracle WebCenter Content are 12.2.1.4.0 and 14.1.2.0.0.
Who can exploit CVE-2026-35270?
CVE-2026-35270 can be exploited by a high privileged attacker with network access via HTTP.
What type of vulnerability is CVE-2026-35270?
CVE-2026-35270 is an easily exploitable vulnerability in the Oracle WebCenter Content product.