A critical vulnerability, CVE-2026-35316, has been identified in Oracle WebCenter Content, part of Oracle Fusion Middleware. The vulnerability exists in the Content Server component and affects versions 12.2.1.4.0 and 14.1.2.0.0. This easily exploitable flaw allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation could result in full takeover of Oracle WebCenter Content, with potential impact extending to other products due to scope change. The CVSS 3.1 base score of 9.9 highlights the severity, encompassing risks to confidentiality, integrity, and availability. Organizations utilizing the affected versions are strongly advised to apply the latest security patches provided by Oracle. Immediate action is recommended to mitigate the risk of unauthorized access and potential system compromise. Users should review Oracle's advisory for detailed mitigation steps and ensure all systems are up to date with the most recent security updates.