CVE-2026-35296 -- CVSS 9.8 Vulnerability Briefing
CVE-2026-35296 | CVSS 9.8 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-35296 is a critical unauthenticated remote vulnerability affecting Oracle WebCenter Sites, a web content management component of Oracle Fusion Middleware, impacting supported versions 12.2.1.4.0 and 14.1.2.0.0.
Technical Detail
The flaw resides in the core WebCenter Sites component and is classified as easily exploitable by Oracle, meaning a remote, unauthenticated attacker can trigger it over the network without requiring any credentials or user interaction. While the full technical mechanism has not been publicly disclosed beyond Oracle's advisory language, the CVSS score of 9.8 indicates the vulnerability likely enables remote code execution or complete compromise of confidentiality, integrity, and availability on the affected host. The attack vector is network-accessible, which significantly broadens the exposure surface for any internet-facing or internally reachable WebCenter Sites deployment.
Exploitation Status
No known exploit has been observed or documented as of June 24, 2026. This vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and no public proof-of-concept code has been confirmed. The absence of known exploitation does not reduce urgency given the critical CVSS score and the unauthenticated attack vector.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with CVE-2026-35296 in available intelligence sources.
What To Do
Apply Oracle's patch for WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 immediately, prioritizing any internet-facing or externally reachable instances. Oracle typically releases fixes through its Critical Patch Update cycle, and administrators should consult the relevant Oracle Security Alert or CPU advisory for the specific patch identifier and installation instructions. If patching cannot be completed immediately, restrict network access to WebCenter Sites administrative and content delivery interfaces using firewall rules or network segmentation to limit exposure to trusted hosts only. Monitor web application and server logs for anomalous unauthenticated requests targeting WebCenter Sites endpoints as a detection signal while remediation is in progress.