CVE-2026-35323: Critical severity Oracle Oracle WebCenter Content vulnerability
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to Oracle WebCenter Content HTTP endpoints. Use firewall rules/ACLs, VPNs, or network segmentation to limit inbound HTTP(S) access to only trusted IPs and management networks; remove or block public Internet access unless strictly required.
- Compensating control
Deploy a Web Application Firewall (WAF) or reverse proxy with virtual-patching rules in front of Oracle WebCenter Content to inspect and block malicious HTTP requests targeting the application.
- Operational
Increase monitoring and incident response readiness for Oracle WebCenter Content: review access and application logs for suspicious activity, isolate any affected hosts if compromise is suspected, perform forensic/IR actions, and rotate credentials and secrets for application and service accounts. Apply vendor security updates or patches for Oracle WebCenter Content as soon as they are released.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35323?
The severity of CVE-2026-35323 is critical with a score of 9.9.
How do I fix CVE-2026-35323?
To fix CVE-2026-35323, upgrade to the latest supported versions of Oracle WebCenter Content.
Who is affected by CVE-2026-35323?
Users of Oracle WebCenter Content versions 12.2.1.4.0 and 14.1.2.0.0 are affected by CVE-2026-35323.
What type of access is required to exploit CVE-2026-35323?
A low privileged attacker with network access via HTTP can exploit CVE-2026-35323.
What components of Oracle Fusion Middleware are impacted by CVE-2026-35323?
CVE-2026-35323 impacts the Content Server component of the Oracle WebCenter Content product.