HIGH 7.5

CVE-2026-35295: Oracle WebCenter Sites Authentication Bypass – High Risk Patch Alert

CVE-2026-35295 is a high-severity vulnerability in Oracle WebCenter Sites that allows a low-privileged user with network access to take complete control of the application. The attacker would need valid credentials and must clear several technical hurdles, but if successful, the compromise is total—affecting confidentiality, integrity, and availability. Organizations running WebCenter Sites 12.2.1.4.0 or 14.1.2.0.0 should treat this as a priority remediation target.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-306
Affected products
2 configuration(s)
Published / Modified
2026-06-17 / 2026-06-17

NVD description (verbatim)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

This vulnerability exists in Oracle WebCenter Sites (versions 12.2.1.4.0 and 14.1.2.0.0) and is rooted in improper authentication or authorization logic, as indicated by the CWE-306 classification (Missing Authentication for Critical Function). The attack vector is network-based via HTTP, requiring an authenticated attacker (low-privilege account) to exploit a condition with high attack complexity. The resulting compromise grants full control over the WebCenter Sites instance, impacting all three security pillars: confidentiality (data exposure), integrity (modification), and availability (disruption or shutdown).

Business impact

A successful exploitation of this vulnerability allows an attacker with internal or low-level access to escalate privileges and gain administrative control over WebCenter Sites—a platform often used for enterprise content management, portals, and digital asset delivery. This can lead to unauthorized access to sensitive business data, defacement or manipulation of published content, service outages affecting customers or internal users, and potential regulatory exposure if personal or financial data is exfiltrated or corrupted.

Affected systems

The vulnerability affects Oracle WebCenter Sites in two specific supported versions: 12.2.1.4.0 and 14.1.2.0.0. Organizations running these versions are at risk; older or newer versions require verification against Oracle's advisory documentation. Any deployment of WebCenter Sites within these version ranges should be inventoried and assessed for exposure.

Exploitability

While the CVSS score reflects a high severity, exploitation is classified as 'difficult'—meaning it is not trivial and requires meeting specific preconditions. An attacker must already possess valid credentials (low-privilege account), have network access to the WebCenter Sites HTTP interface, and overcome high attack complexity barriers. This is not an unauthenticated remote code execution scenario; however, the difficulty threshold is still within the realm of capability for determined threat actors or insider threats. The vulnerability has not been added to CISA's Known Exploited Vulnerabilities catalog, suggesting no active exploitation in the wild at this time.

Remediation

The primary remediation is to apply security patches released by Oracle for this vulnerability. Organizations should consult Oracle's June 2026 Critical Patch Update advisory for version-specific guidance. Interim mitigations may include restricting network access to WebCenter Sites HTTP ports to trusted networks, enforcing stronger authentication controls, and monitoring for suspicious low-privilege account activity. A full inventory of WebCenter Sites deployments and immediate testing of patches in a non-production environment are recommended first steps.

Patch guidance

Oracle has released patches as part of their scheduled Critical Patch Update cycle. Verify the exact patch version and installation steps via Oracle's official security advisory for CVE-2026-35295. Before applying patches to production, test thoroughly in a staging environment to ensure compatibility with custom configurations, extensions, and dependent systems. Plan for any required downtime and communicate it to business stakeholders. After patching, validate that WebCenter Sites functionality remains intact and re-run authentication and authorization tests.

Detection guidance

Monitor WebCenter Sites logs for failed authentication attempts, privilege escalation patterns, unusual HTTP requests to sensitive endpoints, or anomalous user activity from low-privilege accounts. Network intrusion detection systems (IDS) should be configured to flag suspicious HTTP traffic to WebCenter Sites ports. Additionally, implement application-layer monitoring to detect attempts to access protected functions without proper authorization. Baseline normal behavior first, then alert on deviations such as unusual API calls or parameter manipulation by low-privilege users.

Why prioritize this

This vulnerability merits immediate attention because it requires only low-privilege access and results in complete system compromise. Although attack complexity is high, the impact—confidentiality, integrity, and availability—is total. Organizations operating WebCenter Sites in the affected versions should prioritize patching within their change management windows. The lack of public exploitation should not be mistaken for lack of risk; targeted attacks against enterprise content management platforms are common in espionage and data theft scenarios.

Risk score, explained

The CVSS 3.1 score of 7.5 (HIGH) reflects the confluence of critical impacts (C, I, A all high) against a network-accessible service requiring low-privilege authentication. The high attack complexity moderates the score somewhat—this is not an effortless exploit—but the full compromise potential keeps the severity elevated. For organizations with WebCenter Sites as a critical system, functional risk (business impact) may warrant treating this as critical regardless of the CVSS numeric score.

Frequently asked questions

Do I need to patch immediately if I'm running WebCenter Sites 12.2.1.4.0 or 14.1.2.0.0?

Yes. Both versions are explicitly affected. You should prioritize patching as part of your next maintenance window. If WebCenter Sites is internet-facing or accessible to untrusted networks, consider applying interim access controls (network segmentation, stricter authentication) while waiting for the patch window.

Is this vulnerability being actively exploited in the wild?

No—the vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog as of the current disclosure date. However, absence of known public exploitation does not guarantee it won't be targeted. Sophisticated threat actors may exploit high-impact vulnerabilities like this for targeted operations before broader awareness develops.

What should I do if I cannot patch immediately?

Implement compensating controls: restrict HTTP/HTTPS access to WebCenter Sites to trusted IP ranges, enforce multi-factor authentication if available, disable or restrict low-privilege account capabilities where possible, and increase logging and monitoring of authentication events and privilege escalation attempts. These measures reduce exposure while you prepare for patching.

Are other Oracle Fusion Middleware components affected by this vulnerability?

The vulnerability is specific to the WebCenter Sites component. Other Fusion Middleware products (e.g., WebLogic Server, SOA Suite) are separate; however, verify your complete Oracle environment against the full Critical Patch Update advisory to identify any other patches required for your infrastructure.

This analysis is provided for informational purposes and is based on publicly disclosed vulnerability data current as of the publication date. Patch availability, version numbers, and remediation guidance should be verified directly against Oracle's official security advisories. The absence of a vulnerability from CISA's Known Exploited Vulnerabilities catalog does not indicate it will not be exploited. Organizations should assess their own risk tolerance, asset criticality, and compliance obligations when prioritizing remediation. SEC.co makes no warranty regarding the completeness or timeliness of this analysis. Always test patches in a non-production environment before deploying to production systems. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).