CVE-2026-35281 -- CVSS 9.9 Vulnerability Briefing
CVE-2026-35281 | CVSS 9.9 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-35281 is a critical-severity vulnerability in Oracle WebCenter Enterprise Capture, specifically within the Client Bundle component, affecting versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle Fusion Middleware.
Technical Detail
The vulnerability is described as easily exploitable, which based on Oracle's standard advisory language indicates that a low-privileged or unauthenticated network-accessible attacker can trigger the flaw without requiring user interaction or complex preconditions. The full technical description is truncated in available data, but the CVSS score of 9.9 is consistent with a flaw enabling remote code execution or near-complete system compromise, potentially with impact across confidentiality, integrity, and availability. The Client Bundle component suggests the attack surface may involve client-side processing or communication channels between the capture client and server infrastructure.
Exploitation Status
No known exploit has been publicly documented or observed as of June 24, 2026. This vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploit maturity is currently assessed as none, meaning no proof-of-concept, operational, or commoditized exploit code has been confirmed. This status should be monitored closely given the critical CVSS score and the ease-of-exploitation characterization in the advisory.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor associations have been identified in connection with this vulnerability.
What To Do
Organizations running Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 or 14.1.2.0.0 should apply Oracle's patch as part of the relevant Critical Patch Update cycle with high priority, given the 9.9 CVSS score and the easily exploitable classification. If patching cannot be completed immediately, restrict network access to the Client Bundle component and limit exposure of the affected service to trusted internal networks only. Review Oracle's official advisory for any available workarounds or interim mitigations. Monitor for anomalous activity originating from or targeting WebCenter Enterprise Capture services, including unexpected outbound connections or privilege changes associated with the application process. Given the absence of active exploitation today, organizations have a window to remediate before threat actors develop working exploits, but the severity warrants treating this as an urgent patch priority rather than a routine update cycle item.