Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-35284 -- CVSS 9.9 Vulnerability Briefing

CVE-2026-35284 | CVSS 9.9 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-35284 is a critical-severity vulnerability in Oracle WebCenter Enterprise Capture, specifically within the Client Bundle component, affecting versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle Fusion Middleware.

Technical Detail

The vulnerability is described as easily exploitable, which in Oracle's advisory language typically indicates that an attacker requires low or no authentication and minimal interaction to trigger the flaw. Based on the CVSS score of 9.9 and the affected component (Client Bundle), the likely impact involves unauthorized access to sensitive data or the ability to execute arbitrary operations within the application context, potentially including remote code execution or significant privilege escalation. The near-perfect CVSS score suggests the attack vector is network-accessible, requires low privileges, and results in high impact across confidentiality, integrity, and availability, with possible scope change affecting adjacent systems.

Exploitation Status

No known exploit has been observed or documented at this time. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Exploit maturity is assessed as none, meaning no public proof-of-concept or weaponized code has been confirmed as of June 24, 2026. However, the critical severity and easy exploitability rating warrant proactive patching without waiting for confirmed exploitation.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this CVE. Organizations should not interpret the absence of attribution as reduced risk, given the severity of the vulnerability.

What To Do

Apply Oracle's available patch for WebCenter Enterprise Capture versions 12.2.1.4.0 and 14.1.2.0.0 immediately, prioritizing internet-facing or network-accessible deployments. This vulnerability should be treated as high-priority patching given the 9.9 CVSS score and the easily exploitable classification. If patching cannot be completed immediately, restrict network access to the Client Bundle component using firewall rules or network segmentation to limit exposure to trusted hosts only. Monitor application and network logs for anomalous authentication attempts or unexpected client bundle interactions. Verify patch application against Oracle's Critical Patch Update advisory to confirm the correct fix has been applied to all affected instances.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →