CVE-2026-35232 is a medium-severity vulnerability in Oracle Fusion Middleware's Dynamic Monitoring Service component affecting versions 12.2.1.4.0 and 14.1.2.0.0. The vulnerability allows low-privileged attackers with network access to compromise the affected system through HTTP, with potential impacts extending to additional downstream products due to a scope change. The vulnerability is easily exploitable via the network with low attack complexity and requires only low-level privileges. However, successful exploitation requires user interaction from a third party. The attack can result in unauthorized data modification and limited unauthorized data access, with a CVSS 3.1 base score of 5.4 indicating medium risk and impacts to both data confidentiality and integrity. There is currently no evidence of active exploitation in the wild. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog, and the EPSS score of 0.00025 indicates minimal probability of exploitation. Community attention remains low, and the vulnerability is classified as inactive on the Hot List, suggesting this is not a current priority for attackers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2.1.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:fusion_middleware:12.2.1.4.0:*:*:*:*:*:*:* | ||
14.1.2.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:fusion_middleware:14.1.2.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.