CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-35320

Critical · CVSS 9.0

Oracle WebCenter Content — Improper Access Control (unauthenticated network RCE / takeover)

CVSS
9.0
nvd
EPSS
KEV
No
Class
other
CWE-284

Description

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).

Search profile — drives PoC discovery

Symbols Content ServerWebCenter ContentidcplgIdcServiceCHECKIN_UNIVERSALGET_SEARCH_RESULTSSCS_PROTOCOLidc.oracle.com
Keywords CVE-2026-35320Oracle WebCenter ContentContent Serverunauthenticated RCEFusion Middleware exploitWebCenter Content PoC12.2.1.4.014.1.2.0.0CWE-284 Oracle WebCenter
Versions: 12.2.1.4.0 and 14.1.2.0.0

References

Status: enriched · ingested 2026-06-19T00:00:04.000Z · profiled 2026-06-19T00:30:04.000Z