Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-35320

CVE-2026-35320: Oracle WebCenter Auth Bypass Vulnerability

CVE-2026-35320 is an authentication bypass vulnerability in Oracle WebCenter Content that enables unauthenticated attackers to take over the system. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-35320 Overview

CVE-2026-35320 is an improper access control vulnerability [CWE-284] in the Content Server component of Oracle WebCenter Content, part of Oracle Fusion Middleware. The flaw affects supported versions 12.2.1.4.0 and 14.1.2.0.0. An unauthenticated attacker with network access over HTTP can compromise Oracle WebCenter Content. Although exploitation is rated as high complexity, successful attacks change scope and result in full takeover of the product, with impact extending to additional integrated systems.

Critical Impact

Unauthenticated network attackers can achieve full takeover of Oracle WebCenter Content with confidentiality, integrity, and availability impact extending beyond the vulnerable component via scope change.

Affected Products

  • Oracle WebCenter Content 12.2.1.4.0
  • Oracle WebCenter Content 14.1.2.0.0
  • Oracle Fusion Middleware deployments using the affected Content Server component

Discovery Timeline

  • 2026-06-17 - CVE-2026-35320 published to NVD
  • 2026-06-17 - Last updated in NVD database
  • 2026-06-17 - Oracle published security alert cspujun2026

Technical Details for CVE-2026-35320

Vulnerability Analysis

The vulnerability resides in the Content Server component of Oracle WebCenter Content. Oracle classifies the issue as difficult to exploit, requiring specific conditions to be met during the attack. Despite the high attack complexity, no authentication or user interaction is required. The flaw causes a scope change, meaning a successful exploit affects resources beyond the vulnerable Oracle WebCenter Content instance. Successful exploitation can result in complete product takeover, with high confidentiality, integrity, and availability impact across connected systems.

Root Cause

The vulnerability is categorized as improper access control [CWE-284]. The Content Server component fails to correctly enforce authorization boundaries on certain network-accessible request paths. This allows an unauthenticated remote attacker to reach functionality that should be restricted. Oracle has not published technical specifics of the underlying defect, consistent with its Critical Patch Update disclosure practices.

Attack Vector

The attack vector is network-based over HTTP. An attacker sends crafted HTTP requests to an exposed Oracle WebCenter Content Server. No credentials and no victim interaction are required. The high attack complexity indicates that the attacker must satisfy preconditions outside their direct control, such as a specific server configuration or timing. Refer to the Oracle Security Alert for vendor guidance.

Detection Methods for CVE-2026-35320

Indicators of Compromise

  • Unexpected administrative actions or content modifications in Oracle WebCenter Content audit logs from unauthenticated sessions.
  • Anomalous outbound connections originating from the WebCenter Content Server host process.
  • New or modified server-side scripts, custom components, or content templates within the Content Server deployment.
  • HTTP requests to Content Server endpoints from external IP addresses outside expected administrative ranges.

Detection Strategies

  • Enable verbose audit logging in Oracle WebCenter Content and forward logs to a centralized SIEM for correlation.
  • Inspect HTTP access logs for requests targeting Content Server administrative or service URIs without preceding authentication events.
  • Baseline the file system of the Content Server installation and alert on unauthorized changes to deployment directories.

Monitoring Recommendations

  • Monitor process lineage on Oracle WebCenter Content hosts for unexpected child processes spawned from the application server.
  • Alert on egress traffic from the middleware tier to non-corporate destinations, which may indicate post-exploitation activity.
  • Track authentication failures followed by successful privileged actions, which may indicate access control bypass.

How to Mitigate CVE-2026-35320

Immediate Actions Required

  • Apply the security fix referenced in the Oracle Critical Patch Update cspujun2026 to all affected Oracle WebCenter Content deployments.
  • Restrict network access to Oracle WebCenter Content Server endpoints so they are only reachable from trusted internal networks.
  • Review audit logs and file system integrity on Content Server hosts for signs of prior exploitation.
  • Inventory all WebCenter Content instances and confirm version levels against 12.2.1.4.0 and 14.1.2.0.0.

Patch Information

Oracle addressed CVE-2026-35320 in the June 2026 Critical Patch Update. Administrators should download and apply the patches documented in the Oracle Security Alert. Oracle recommends applying Critical Patch Update fixes without delay because attackers reverse-engineer patches to develop exploits.

Workarounds

  • Place Oracle WebCenter Content behind an authenticating reverse proxy or web application firewall that blocks unauthenticated access to Content Server URIs.
  • Disable or firewall-restrict any Content Server services not required for production operation.
  • Enforce network segmentation so that only application tiers requiring document services can reach the Content Server.
  • If patching is delayed, take affected instances offline until fixes can be applied.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.