Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-35283 -- CVSS 9.9 Vulnerability Briefing

CVE-2026-35283 | CVSS 9.9 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-35283 is a critical-severity vulnerability in Oracle WebCenter Enterprise Capture, specifically within the Client Bundle component, affecting versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle Fusion Middleware.

Technical Detail

The vulnerability is described as easily exploitable, which in Oracle's advisory language typically indicates that an attacker requires low or no authentication and minimal interaction to trigger the flaw. Based on the CVSS score of 9.9 and the affected component (Client Bundle), the likely impact involves unauthorized access to sensitive data or the ability to execute arbitrary operations within the application context, potentially including remote code execution or significant privilege escalation. The near-maximum CVSS score suggests the vulnerability affects confidentiality, integrity, and availability, and may be exploitable over the network without requiring local access.

Exploitation Status

No known exploit has been observed or documented as of June 24, 2026. This vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog. There is no public proof-of-concept code confirmed at this time. Despite the absence of known exploitation, the critical severity and ease-of-exploitation characterization warrant proactive remediation rather than a wait-and-see posture.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this CVE as of the date of this briefing.

What To Do

Apply Oracle's patch for WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 immediately, prioritizing internet-facing or network-accessible deployments. This vulnerability should be treated as high-priority patching given the 9.9 CVSS score and the easily exploitable characterization. If patching cannot be completed immediately, restrict network access to the Client Bundle component and limit exposure to trusted internal networks only. Monitor Oracle's Critical Patch Update advisory for any updated guidance or additional affected version disclosures. Audit logs for anomalous access patterns targeting WebCenter Enterprise Capture endpoints as a precautionary detection measure.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →