CVE-2026-35318: Oracle WebCenter Sites Privilege Escalation (CVSS 8.8)
Oracle WebCenter Sites, a content management platform, contains a privilege escalation vulnerability that allows low-privileged attackers with network access to gain full administrative control. An attacker with basic user credentials can exploit this flaw via HTTP to completely compromise the system, potentially accessing, modifying, or deleting sensitive content and disrupting service availability. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.8 HIGH · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-284
- Affected products
- 2 configuration(s)
- Published / Modified
- 2026-06-17 / 2026-06-17
NVD description (verbatim)
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-35318 is a CWE-284 (Improper Access Control) vulnerability in Oracle WebCenter Sites. The flaw has a low attack complexity and requires only low privilege access to trigger, making it particularly dangerous in multi-tenant or shared hosting scenarios where legitimate user accounts are commonplace. The vulnerability is network-accessible via HTTP and requires no user interaction. When successfully exploited, an attacker gains the same privileges and access as the victim, with potential for full system compromise given WebCenter Sites' role as a content management system.
Business impact
Compromise of WebCenter Sites creates significant business risk. Attackers could steal confidential content, alter published materials, inject malicious code, or disable the platform entirely. For organizations using WebCenter Sites for customer-facing content delivery or internal collaboration, this could result in reputational damage, compliance violations, and operational downtime. The ease of exploitation—requiring only a low-privileged account and network access—means insider threats or compromised user credentials become immediate attack vectors.
Affected systems
Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 are confirmed affected. Organizations running these specific versions should prioritize assessment and remediation. Later versions may have remediation available; verify your deployment version and consult Oracle's security advisory for the complete list of patched versions.
Exploitability
This vulnerability is highly exploitable. It requires only network access and low-privilege credentials—conditions typically met in most organizational environments where WebCenter Sites serves multiple users. The low attack complexity and absence of user interaction requirements mean attacks could be automated and scaled. However, since an initial valid user account is necessary, the threat is elevated among organizations where user provisioning is loose or where compromised credentials circulate.
Remediation
Apply security patches from Oracle addressing CVE-2026-35318 immediately. Contact your Oracle support account or consult Oracle's June 2026 Critical Patch Update advisories for specific patch versions targeting your deployment version. Test patches in a staging environment before production rollout to ensure compatibility with custom WebCenter Sites configurations. Consider also reviewing and restricting low-privilege user access levels to limit the scope of lateral movement if initial compromise occurs.
Patch guidance
Check Oracle's June 2026 Critical Patch Update announcements for patches addressing this CVE for your specific version of WebCenter Sites. Verify patch compatibility with any custom extensions or integrations before applying. Plan a maintenance window for production systems, as some patches may require service restart. Document your baseline configuration and have rollback procedures ready in case unforeseen issues arise during patching.
Detection guidance
Monitor WebCenter Sites logs for unusual privilege escalation attempts, unexpected administrative actions originating from low-privilege accounts, and anomalous HTTP requests to privileged endpoints. Review access logs for accounts making requests inconsistent with their role. Inspect authentication and authorization logs for failed escalation attempts that may indicate exploitation probing. Set alerts on successful privilege elevation events and bulk content modifications by normally-restricted users.
Why prioritize this
This vulnerability scores CVSS 8.8 (HIGH) and combines ease of exploitation with complete system compromise potential. The low barrier to initial access—requiring only a valid user account—makes it a high-priority target for threat actors. Given the centrality of content management systems to many organizations' operations, swift patching prevents both immediate compromise and lateral movement risks.
Risk score, explained
The CVSS 3.1 score of 8.8 reflects the combination of network accessibility, low attack complexity, minimal privilege requirements, and severe impact across confidentiality, integrity, and availability. While an attacker needs a valid account (reducing score from critical), the ease of obtaining such credentials through hiring, phishing, or credential stuffing means the practical risk is severe. The lack of current KEV status does not diminish the vulnerability's urgency given its exploitability profile.
Frequently asked questions
Do I need valid credentials to exploit this vulnerability?
Yes. An attacker must possess low-privilege user credentials for the WebCenter Sites instance. This means internal threats, compromised accounts, or weak default credentials become immediate risks. Organizations should audit access controls and credential hygiene as part of their mitigation strategy.
What is the difference between versions 12.2.1.4.0 and 14.1.2.0.0?
Both versions are confirmed vulnerable; the difference is primarily in feature sets and maturity. Version 14.1.2.0.0 is newer. You should check Oracle's patch advisories to confirm which patch versions address this CVE for each release, as remediation may differ.
Does this affect WebCenter Portal or other WebCenter products?
This CVE specifically affects WebCenter Sites. Related WebCenter products (Portal, Content, Collaboration) have separate vulnerability records. Do not assume this patch applies to your other Oracle WebCenter components; consult Oracle's advisory for complete scope.
What should I do if I cannot patch immediately?
Implement network-level controls to restrict HTTP access to WebCenter Sites to only trusted internal networks or IP ranges. Review and minimize the number of low-privilege user accounts, audit their activity closely, and enforce strong password policies. These are temporary mitigations only—prioritize patching as your primary remediation.
This analysis is based on publicly available information from Oracle vulnerability disclosures. Specific patch version numbers and compatibility details must be verified against the official Oracle Critical Patch Update advisory for June 2026. Organizations should conduct independent testing of patches before production deployment. This document is for informational purposes and does not constitute professional security advice; consult with qualified security professionals for your specific environment. No exploit code or detailed attack steps are provided; responsible disclosure practices are observed. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-35262HIGHOracle Data Integrator Authentication Bypass – Data Exposure Risk
- CVE-2026-35269HIGHOracle Identity Manager REST WebServices Authentication Bypass
- CVE-2026-35271HIGHOracle PeopleSoft WebLogic Unauthenticated Data Access Vulnerability (CVSS 8.7)
- CVE-2026-35275HIGHOracle VM VirtualBox Shared Folders Privilege Escalation Vulnerability (CVSS 7.5)
- CVE-2026-35277HIGHOracle REST Data Services Authorization Bypass
- CVE-2026-35311HIGHOracle WebLogic Server Remote Takeover via Low-Privilege Access Control Flaw
- CVE-2026-35314HIGHOracle Access Manager Authentication Bypass (CVSS 7.3)
- CVE-2026-35315HIGHOracle WebCenter Content Remote Takeover via Low-Privilege HTTP Access