CVE-2026-35325: Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server)
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A high-severity vulnerability exists in the Oracle WebCenter Content product (Content Server component) of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. The flaw is reachable over the network via HTTP and requires only a low-privileged account, with no user interaction needed. Successful exploitation gives an attacker full control of the Content Server instance, impacting confidentiality, integrity, and availability. No fix version has been published yet; HarborGuard is tracking the advisory and will make a patched-image rebuild available as soon as Oracle ships an upstream fix.
HarborGuard Coverage
Detection for CVE-2026-35325 is available across every HarborGuard environment: the CVE is ingested from upstream advisory feeds within minutes of publication and matched against all container images in customer registries and CI/CD pipelines, including custom-built images derived from Oracle WebCenter Content base layers. Any image running an affected version (12.2.1.4.0 or 14.1.2.0.0) will surface in scan results automatically.
AvailableHarborGuard is capable of scoring this CVE at its published CVSS 3.1 base score of 8.8 (HIGH) and weighting that score against each customer environment's compliance policy to determine urgency and routing. Findings can be directed to the appropriate team inbox within each customer organization based on policy-defined ownership rules.
AvailableBecause no upstream fix version has been published for CVE-2026-35325, HarborGuard re-evaluates the advisory on every ingest cycle and will make a patched-image rebuild available the moment Oracle publishes a corrected release. For customers with auto-remediation enabled, the rebuild, regression test run, and pull request against affected workloads will trigger automatically at that point, where compliance policy permits.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the Content Server over the network via HTTP; the service must be exposed to the attacker's network segment.
- AuthenticationRequired
A low-privilege account is sufficient; no administrative or elevated credentials are needed to trigger the vulnerability.
- Victim interactionNot required
No user interaction is required; the attacker can exploit the vulnerability entirely without involving another person.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other variable environmental factors.
Blast Radius
- A successful attacker reads all content managed by the Content Server, including stored documents, metadata, and any credentials or tokens held in the system.
- The attacker can modify or delete persisted content records, configuration, and access-control settings within the affected WebCenter Content instance.
- The attacker can crash or render the Content Server unavailable, disrupting document management and any workflows that depend on it.
- Full system takeover is achievable, meaning the attacker can install persistent backdoors or pivot to other services reachable from the compromised host.
How HarborGuard Handles This
Available on HarborGuard: CVE-2026-35325 is flagged as HIGH severity with a CVSS score of 8.8, and detection is active for any image running Oracle WebCenter Content 12.2.1.4.0 or 14.1.2.0.0. Because Oracle has not yet published a fix, HarborGuard monitors the advisory on every ingest cycle and will trigger a patched-image rebuild automatically the moment an upstream fix is released. In the interim, compensating controls worth considering include restricting network-policy access to the Content Server so that only authorized internal clients can reach it over HTTP, applying egress filtering to limit lateral movement from a compromised instance, and auditing low-privileged accounts with HTTP access to reduce the pool of credentials an attacker could use. For customers with auto-remediation enabled, a rebuilt image, regression test run, and PR against affected workloads will be initiated as soon as a fix version is available, where compliance policy permits.
- Oracle Corporation / Oracle WebCenter Content12.2.1.4.0 · 14.1.2.0.0
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H