HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-35293Published Modified CNA oracle

CVE-2026-35293: Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
9.8
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A critical unauthenticated remote compromise vulnerability affects Oracle WebCenter Sites version 14.1.2.0.0, a component of Oracle Fusion Middleware. An attacker with network access over HTTP requires no credentials and no victim interaction to exploit this flaw. Successful exploitation results in full takeover of the affected WebCenter Sites instance, granting the attacker read, write, and availability control over the system. No fix versions have been published by Oracle; HarborGuard is tracking the advisory and will surface a patched rebuild the moment upstream publishes a fix.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from Oracle and upstream vulnerability feeds within minutes of publication and matched against all customer images, including custom-built images derived from Oracle Fusion Middleware base layers. Any image containing Oracle WebCenter Sites 14.1.2.0.0 is flagged automatically as affected.

Available
Triage

HarborGuard scores this CVE at CVSS 9.8 (Critical) and weights it against each customer environment's compliance policy to determine escalation priority. Triage alerts are routed to the appropriate team inbox within each customer organization based on registry ownership and policy configuration.

Available
Patch

Because no upstream fix version has been published, HarborGuard re-checks the Oracle advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment Oracle ships a remediated release. In the interim, customers can apply compensating controls such as network-policy isolation and egress filtering through HarborGuard's policy enforcement capabilities.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the Oracle WebCenter Sites HTTP service over the network; there is no local or physical access requirement.

  • AuthenticationNot required

    No credentials of any kind are needed; the vulnerability is exploitable by any unauthenticated network caller.

  • Victim interactionNot required

    No user action or social engineering is required; the attacker acts entirely without victim participation.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and requires no special timing, race conditions, or environmental preconditions.

Blast Radius

  • A successful attacker reads all data stored in or accessible by Oracle WebCenter Sites, including site content, configuration, and any credentials held by the application.
  • A successful attacker modifies or destroys persisted content, configuration records, and application state within Oracle WebCenter Sites.
  • A successful attacker crashes or degrades the WebCenter Sites service, making it unavailable to legitimate users.
  • Full system takeover means the attacker can pivot from the compromised instance to other systems reachable from the same host or network segment.

How HarborGuard Handles This

Available on HarborGuard: this CVE is monitored continuously against all customer images that include Oracle WebCenter Sites 14.1.2.0.0, with match results surfaced in each environment's vulnerability dashboard. Because Oracle has not yet published a fix version, no patched-image rebuild is available at this time. HarborGuard re-evaluates the Oracle advisory on every ingest cycle; when a fix is released, a patched-image rebuild will become available immediately, and customers with auto-remediation enabled will receive a rebuilt image, a regression-test run, and a PR opened against affected workloads. In the interim, the recommended compensating controls are: restricting network access to WebCenter Sites HTTP endpoints via Kubernetes network policy or firewall rules, applying egress filtering to limit lateral movement from a compromised instance, and auditing any credentials or secrets accessible to the WebCenter Sites process. For environments where compliance policy permits, HarborGuard can enforce a block-on-deploy rule for images carrying this CVE until a patched version is available.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Oracle WebCenter Sites
    14.1.2.0.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References