HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-35321Published Modified CNA oracle

CVE-2026-35321: Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Metrics

CVSS v3.1
9.9
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A critical-severity vulnerability affects the Content Server component of Oracle WebCenter Content (versions 12.2.1.4.0 and 14.1.2.0.0), part of Oracle Fusion Middleware. The flaw is reachable over HTTP from the network and requires only a low-privilege account, with no victim interaction needed; the scope of impact extends beyond the directly compromised component to additional products in the environment. Successful exploitation gives an attacker full takeover of Oracle WebCenter Content, including complete control over confidentiality, integrity, and availability. HarborGuard is tracking this advisory and will make a patched-image rebuild available the moment Oracle publishes a fix version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from Oracle and upstream security feeds within minutes of publication and matched against all customer images, including custom-built images that package Oracle WebCenter Content components. Any image in a connected registry or CI pipeline running version 12.2.1.4.0 or 14.1.2.0.0 is flagged automatically.

Available
Triage

HarborGuard scores this CVE at 9.9 CRITICAL using the published CVSS v3.1 vector and surfaces it at the top of the severity queue in each customer environment. Per-environment compliance policy weighting and team-routing rules are applied so the alert reaches the right inbox without requiring manual triage.

Available
Patch

Because no fix version has been published by Oracle, HarborGuard re-evaluates the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. For customers with auto-remediation enabled, the rebuild, regression-test run, and PR against affected workloads will be initiated without delay once a fix version becomes available.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the Oracle WebCenter Content Server over the network via HTTP; no local or physical access is needed.

  • AuthenticationRequired

    Any low-privilege account is sufficient; no administrative credentials are required, but the attacker must hold at least one valid user account.

  • Victim interactionNot required

    No user action or social engineering is needed; the attacker can exploit the vulnerability entirely on their own.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and requires no special race conditions, memory-layout knowledge, or other environmental prerequisites.

Blast Radius

  • Reads all content stored in Oracle WebCenter Content, including documents, records, and associated metadata.
  • Modifies or deletes persisted content and configuration data within the Content Server.
  • Crashes or renders the Content Server unavailable, disrupting all workflows and integrations that depend on it.
  • Pivots to additional products and services in the same environment due to the scope change indicated in the CVSS vector.

How HarborGuard Handles This

Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-35321, HarborGuard monitors the advisory on every ingest cycle and will trigger a patched-image rebuild and, for customers with auto-remediation enabled, open a PR against affected workloads the moment a fix version is released. In the interim, compensating controls are recommended: apply network-policy rules to restrict HTTP access to the Content Server to only known, trusted source CIDRs; enforce egress filtering to limit lateral movement if the service is compromised; and consider feature-flag gating or temporary isolation of the affected component if your workload permits it. Environments with auto-remediation enabled will receive the rebuild plus regression-test results immediately upon upstream fix availability, with no manual intervention required. Where compliance policy requires review before merge, the PR is opened for human approval rather than merged automatically.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Oracle WebCenter Content
    12.2.1.4.0 · 14.1.2.0.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
References