CVE-2026-35316: Critical severity Oracle Oracle WebCenter Content vulnerability
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to Oracle WebCenter Content HTTP endpoints: block or limit HTTP access at the network perimeter (firewall/ACL) so only trusted IPs or networks can reach the service; do not allow direct public Internet access.
- Compensating control
Deploy a web application firewall (WAF) or equivalent HTTP-layer filtering in front of Oracle WebCenter Content to detect and block exploit attempts targeting the product's HTTP interface.
- Operational
Monitor and review HTTP access logs and application logs for indicators of exploitation against Oracle WebCenter Content; isolate and perform incident response on any systems showing signs of compromise, given the reported risk of full takeover.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35316?
CVE-2026-35316 has a critical severity score of 9.9.
How do I fix CVE-2026-35316?
The recommended fix for CVE-2026-35316 is to update to the latest supported version of Oracle WebCenter Content.
What does CVE-2026-35316 affect?
CVE-2026-35316 affects the Oracle WebCenter Content product of Oracle Fusion Middleware, specifically versions 12.2.1.4.0 and 14.1.2.0.0.
Can CVE-2026-35316 be exploited remotely?
Yes, CVE-2026-35316 can be easily exploited by a low privileged attacker with network access via HTTP.
What type of issues does CVE-2026-35316 cause?
CVE-2026-35316 can lead to compromise of confidentiality, integrity, and availability of the affected systems.