A critical vulnerability (CVE-2026-35280) has been identified in Oracle WebCenter Enterprise Capture, part of Oracle Fusion Middleware. This vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. It allows a low-privileged attacker with network access via T3 or IIOP protocols to compromise the system, potentially leading to full takeover. The vulnerability is easily exploitable, and while it resides in the WebCenter Enterprise Capture component, it may impact additional products due to scope changes. The CVSS score of 9.9 indicates a high severity level. Organizations using the affected versions of Oracle Fusion Middleware should prioritize applying the relevant security patches to mitigate this risk. Until patched, users are advised to restrict network access to the affected systems and monitor for unusual activity.
CRITICAL
CVSS 9.9
CVE-2026-35280
2026-08-28
Critical Vulnerability in Oracle WebCenter Enterprise Capture (CVE-2026-35280)
A critical vulnerability (CVE-2026-35280) allows low-privileged attackers to take over Oracle WebCenter Enterprise Capture via network access. Affected versions include 12.2.1.4.0 and 14.1.2.0.0 of Oracle Fusion Middleware platforms.