Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Oracle WebCenter Sites allows any unauthenticated attacker with network access through HTTP to send crafted requests that result in a full takeover of the application. This enables the attacker to exfiltrate data, modify content, and disrupt services, compromising the confidentiality, integrity, and availability of the affected instance.

Affected Systems

Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 are impacted. No other supported releases are listed as affected.

Risk and Exploitability

The assignment earned a CVSS v3.1 score of 9.8, categorising it as critical. The EPSS score of less than 1% indicates a low but non‑zero exploitation probability. The vulnerability is not in the CISA KEV catalog. Attackers can exploit it over the network via HTTP without authentication, making it remotely exploitable and easily usable for takeover.

Generated by OpenCVE AI on August 2, 2026 at 21:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the July 2026 Oracle CPU patch for WebCenter Sites.
  • Restrict HTTP access to the WebCenter Sites instance to trusted networks only.
  • Enforce TLS and configure the server to reject plain HTTP connections.

Generated by OpenCVE AI on August 2, 2026 at 21:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP-based WebCenter Sites Takeover Vulnerability

Tue, 28 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle WebCenter Sites
Weaknesses CWE-284
CWE-95

Mon, 27 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle WebCenter Sites
Weaknesses CWE-284
CWE-95

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:56:35.112Z

Reserved: 2026-07-08T15:51:40.544Z

Link: CVE-2026-60551

cve-icon Vulnrichment

Updated: 2026-07-27T11:23:04.951Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:00:07Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function