CVE-2026-35293 -- CVSS 9.8 Vulnerability Briefing
CVE-2026-35293 | CVSS 9.8 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-35293 is a critical, easily exploitable vulnerability in Oracle WebCenter Sites version 14.1.2.0.0, a component of Oracle Fusion Middleware used for web content management and digital experience delivery.
Technical Detail
The vulnerability exists within the core WebCenter Sites component and carries a CVSS score of 9.8, indicating that exploitation requires no authentication and no user interaction, and is achievable over the network. Oracle's advisory characterizes it as "easily exploitable," which typically corresponds to a low-complexity attack path such as unauthenticated remote code execution or a complete authentication bypass leading to full system compromise. The precise technical mechanism has not been fully disclosed in available public data, but the severity score and exploitability rating are consistent with a pre-authentication flaw that could allow an attacker to take control of the affected system.
Exploitation Status
No known exploit code has been observed or confirmed at this time. This vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog. The exploit maturity is assessed as no known exploit, meaning no public proof-of-concept or active in-the-wild exploitation has been documented as of June 24, 2026. However, the critical CVSS score and Oracle's "easily exploitable" classification make this a high-priority candidate for rapid weaponization once additional technical details become available.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor associations have been established for this CVE. Organizations should not interpret the absence of attribution as an indicator of low risk, given the severity of the vulnerability and the typical interest nation-state and financially motivated actors show in Oracle Fusion Middleware products.
What To Do
Apply Oracle's patch for WebCenter Sites 14.1.2.0.0 as part of Oracle's Critical Patch Update cycle immediately, treating this as a priority-one remediation given the 9.8 CVSS score and the unauthenticated attack vector. Organizations that cannot patch immediately should restrict network access to WebCenter Sites administrative interfaces and content delivery endpoints using perimeter controls, and ensure the application is not directly exposed to the internet. Monitor web application firewall and network logs for anomalous requests targeting WebCenter Sites endpoints, particularly those involving unexpected HTTP methods, unusual parameter structures, or requests from untrusted source IPs. Confirm patch application through change management records and validate the installed version post-update.