Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-35285 -- CVSS 9.9 Vulnerability Briefing

CVE-2026-35285 | CVSS 9.9 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-35285 is a critical-severity vulnerability in Oracle WebCenter Enterprise Capture, a component of Oracle Fusion Middleware, specifically affecting the Client Bundle component in versions 12.2.1.4.0 and 14.1.2.0.0.

Technical Detail

The vulnerability is described as easily exploitable, which in Oracle's advisory language typically indicates that an attacker requires no specialized conditions or complex interaction to trigger the flaw. Based on the CVSS score of 9.9 and the affected component, the flaw likely permits unauthenticated or low-privilege remote code execution or significant privilege escalation against the WebCenter Enterprise Capture service. The near-maximum CVSS score suggests a combination of network accessibility, low attack complexity, and high impact across confidentiality, integrity, and availability, consistent with a critical RCE or authentication bypass class vulnerability in the Client Bundle component.

Exploitation Status

No known exploit has been publicly documented or observed as of June 24, 2026. This vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. There is no confirmed proof-of-concept code or active exploitation activity at this time, though the low attack complexity rating increases the risk that a functional exploit could be developed relatively quickly once researchers examine the patch differential.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this CVE as of the date of this briefing.

What To Do

Organizations running Oracle WebCenter Enterprise Capture versions 12.2.1.4.0 or 14.1.2.0.0 should apply Oracle's available patch as a high priority given the critical CVSS score of 9.9 and the easily exploitable classification. Patch guidance should be sourced from Oracle's Critical Patch Update advisory for this CVE. If immediate patching is not feasible, restrict network access to the WebCenter Enterprise Capture service at the perimeter and limit exposure of the Client Bundle component to trusted internal networks only. Monitor application and network logs for anomalous access patterns targeting WebCenter Capture endpoints. Given the severity and ease of exploitation, treat this as a priority remediation item within your next patch cycle and do not defer beyond 30 days.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →