Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-35296

CVE-2026-35296: Oracle WebCenter Sites Auth Bypass Flaw

CVE-2026-35296 is an authentication bypass vulnerability in Oracle WebCenter Sites that allows attackers to take over the system without credentials. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-35296 Overview

CVE-2026-35296 is a critical vulnerability in Oracle WebCenter Sites, a component of Oracle Fusion Middleware. The flaw allows an unauthenticated remote attacker to take over affected installations using only network access over HTTP. Oracle disclosed the issue in the June 2026 Critical Patch Update. The vulnerability is mapped to [CWE-306] Missing Authentication for Critical Function, indicating that a security-relevant operation can be reached without credentials. Affected releases are Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0. Successful exploitation results in full compromise of confidentiality, integrity, and availability of the WebCenter Sites instance.

Critical Impact

Unauthenticated attackers can fully take over Oracle WebCenter Sites instances over the network with no user interaction.

Affected Products

  • Oracle WebCenter Sites 12.2.1.4.0
  • Oracle WebCenter Sites 14.1.2.0.0
  • Oracle Fusion Middleware deployments embedding the affected WebCenter Sites component

Discovery Timeline

  • 2026-06-17 - CVE-2026-35296 published to NVD
  • 2026-06-17 - Last updated in NVD database
  • June 2026 - Oracle releases fix in the Critical Patch Update for June 2026

Technical Details for CVE-2026-35296

Vulnerability Analysis

The vulnerability resides in the WebCenter Sites component of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is easily exploitable and reachable by an unauthenticated attacker over HTTP. The CWE classification [CWE-306] indicates that a critical function in the application is exposed without an authentication check.

Because the attack requires no privileges and no user interaction, any internet-reachable WebCenter Sites instance running an affected version is at direct risk. Successful exploitation yields takeover of the WebCenter Sites application, including the ability to read or modify content, alter site behavior, and disrupt service availability. EPSS currently estimates a 0.483% exploitation probability, but the trivial attack profile typically attracts opportunistic scanning soon after disclosure.

Root Cause

The root cause is a missing authentication check on a critical function within WebCenter Sites. A code path that should require authenticated and authorized access is reachable through standard HTTP requests without credentials. Oracle has not published the specific endpoint or function in public materials and refers customers to the June 2026 Critical Patch Update for remediation details.

Attack Vector

The attack vector is network-based HTTP traffic against the WebCenter Sites service. An attacker sends crafted HTTP requests directly to the exposed application. No phishing, prior foothold, or valid session is required. Instances that expose WebCenter Sites endpoints to untrusted networks present the highest exposure. See the Oracle Security Alert - June 2026 CPU for vendor guidance.

No public proof-of-concept code or exploit has been verified at the time of writing, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Detection Methods for CVE-2026-35296

Indicators of Compromise

  • Unauthenticated HTTP requests to WebCenter Sites administrative or content management endpoints originating from unexpected source IPs.
  • New or modified site content, templates, or asset definitions that do not correlate to a known editor session or change ticket.
  • Creation of new user accounts, role assignments, or privileged sessions in WebCenter Sites without corresponding identity provider activity.
  • Outbound connections from the WebCenter Sites application server to unfamiliar destinations following anomalous inbound HTTP traffic.

Detection Strategies

  • Review WebCenter Sites and fronting web server access logs for requests to sensitive paths that return success responses without an authenticated session cookie.
  • Correlate application logs with authentication logs to identify privileged actions that lack a preceding successful login event.
  • Compare deployed application server binaries and configuration against a known-good baseline to detect tampering.

Monitoring Recommendations

  • Forward web server, application server, and WebCenter Sites audit logs to a centralized analytics platform for retention and correlation.
  • Alert on spikes in HTTP 4xx/5xx errors against WebCenter Sites endpoints, which may indicate exploitation attempts and probing.
  • Monitor for process creation, file writes, and outbound network connections initiated by the WebCenter Sites JVM process.

How to Mitigate CVE-2026-35296

Immediate Actions Required

  • Apply the Oracle Critical Patch Update for June 2026 to Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 as the primary remediation.
  • Inventory all WebCenter Sites instances, including non-production environments, and confirm patch status for each.
  • Restrict network exposure of WebCenter Sites administrative interfaces to trusted management networks until patching is complete.
  • Review WebCenter Sites accounts, roles, and recent content changes for signs of unauthorized activity.

Patch Information

Oracle addressed CVE-2026-35296 in the June 2026 Critical Patch Update. Patch packages and version-specific guidance are available in the Oracle Security Alert - June 2026 CPU. Customers should follow Oracle's documented patch application procedure for Fusion Middleware and validate the WebCenter Sites build identifier after deployment.

Workarounds

  • Place a web application firewall (WAF) in front of WebCenter Sites and block unauthenticated access to administrative and content management paths.
  • Enforce network segmentation so that the WebCenter Sites application server is not directly reachable from the public internet.
  • Require VPN or zero-trust access for administrative endpoints until the patch has been applied and validated.
  • Increase logging verbosity on the application server and fronting reverse proxy during the remediation window to support investigation.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.