CVE-2026-35315: Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
This is a high-severity vulnerability in the Content Server component of Oracle WebCenter Content, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. The flaw is reachable over the network via HTTP and requires only a low-privileged account, with no victim interaction needed. Successful exploitation gives an attacker full takeover of the affected Oracle WebCenter Content instance, impacting confidentiality, integrity, and availability. No fix version has been published by Oracle at this time; HarborGuard is tracking the advisory and will surface a patched-image rebuild the moment upstream ships a fix.
HarborGuard Coverage
Detection for CVE-2026-35315 is available across every HarborGuard environment: the CVE is ingested from upstream advisory feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Oracle WebCenter Content components. Any image in a customer registry or build pipeline running an affected version (12.2.1.4.0 or 14.1.2.0.0) is flagged automatically.
AvailableTriage is available using the CVSS 3.1 base score of 8.8 (HIGH), weighted further by each customer organization's compliance policy to prioritize or suppress alerts according to their environment's risk tolerance. Routed findings land in the appropriate team inbox inside each customer org based on image ownership and policy configuration.
AvailableBecause no fix version has been published by Oracle, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available the moment upstream ships a corrected release. In the interim, customers can apply compensating controls through HarborGuard's network-policy and egress-filtering recommendations surfaced on the finding detail page.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the Content Server over the network via HTTP; no local or physical access is needed.
- AuthenticationRequired
Any low-privileged account on the system is sufficient; anonymous access alone is not enough to exploit this vulnerability.
- Victim interactionNot required
No action from another user or administrator is needed; the attacker can exploit the vulnerability entirely on their own.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other variable environmental factors.
Blast Radius
- Reads all content, documents, and metadata stored in the Oracle WebCenter Content repository, including any sensitive or access-controlled files.
- Modifies or deletes persisted content, repository metadata, and configuration data held by the Content Server.
- Crashes or degrades the Content Server service, making document management and retrieval unavailable to dependent applications and users.
- Achieves full system takeover, potentially enabling lateral movement to other services or hosts reachable from the compromised Content Server.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-35315 is active across customer environments scanning images that include Oracle WebCenter Content 12.2.1.4.0 or 14.1.2.0.0. Because Oracle has not yet published a fix, no patched-image rebuild is currently available; HarborGuard monitors the advisory on every ingest cycle and will surface a rebuild automatically when upstream ships a corrected version. While no patch exists, customers can reduce exposure by applying network-policy isolation to restrict HTTP access to Content Server to known, authorized sources only, and by enabling egress filtering to limit outbound connections from affected workloads. For customers who opt into auto-remediation, a rebuild, regression-test run, and PR against affected workloads will be triggered automatically the moment a fix version is published, with no manual intervention required.
- Oracle Corporation / Oracle WebCenter Content12.2.1.4.0 · 14.1.2.0.0
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H