CVE-2026-35283 -- CVSS 9.9 Vulnerability Briefing
CVE-2026-35283 | CVSS 9.9 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-35283 is a critical-severity vulnerability in Oracle WebCenter Enterprise Capture, specifically within the Client Bundle component, affecting versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle Fusion Middleware.
Technical Detail
The vulnerability is described as easily exploitable, which in Oracle's advisory language typically indicates that an attacker requires low or no authentication and minimal interaction to trigger the flaw. Based on the CVSS score of 9.9 and the affected component (Client Bundle), the likely impact involves unauthorized access to sensitive data or the ability to execute arbitrary operations within the application context, potentially including remote code execution or significant privilege escalation. The near-maximum CVSS score suggests the vulnerability affects confidentiality, integrity, and availability, and may be exploitable over the network without requiring local access.
Exploitation Status
No known exploit has been observed or documented as of June 24, 2026. This vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog. There is no public proof-of-concept code confirmed at this time. Despite the absence of known exploitation, the critical severity and ease-of-exploitation characterization warrant proactive remediation rather than a wait-and-see posture.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this CVE as of the date of this briefing.
What To Do
Apply Oracle's patch for WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 immediately, prioritizing internet-facing or network-accessible deployments. This vulnerability should be treated as high-priority patching given the 9.9 CVSS score and the easily exploitable characterization. If patching cannot be completed immediately, restrict network access to the Client Bundle component and limit exposure to trusted internal networks only. Monitor Oracle's Critical Patch Update advisory for any updated guidance or additional affected version disclosures. Audit logs for anomalous access patterns targeting WebCenter Enterprise Capture endpoints as a precautionary detection measure.