A critical vulnerability, CVE-2026-35323, has been identified in Oracle WebCenter Content, part of Oracle Fusion Middleware. This vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0 of the Content Server component. The flaw allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation could result in full takeover of the Oracle WebCenter Content, leading to significant impacts on confidentiality, integrity, and availability. The CVSS 3.1 base score of 9.9 underscores the severity, indicating a high risk of exploitation. Organizations utilizing the affected versions of Oracle WebCenter Content are strongly advised to apply the latest security patches provided by Oracle. Mitigation measures should include network segmentation, restricting unnecessary access, and monitoring for suspicious activity. Immediate action is recommended to prevent potential breaches and ensure the security of affected systems.
CRITICAL
CVSS 9.9
CVE-2026-35323
2026-08-24
Critical Vulnerability in Oracle WebCenter Content (CVE-2026-35323)
A critical vulnerability (CVE-2026-35323) allows low-privileged attackers to take over Oracle WebCenter Content via HTTP. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. CVSS 9.9, requiring immediate patching.