Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle WebCenter Sites has a vulnerability that allows an attacker with low privileges and network access via HTTP to take control of the application. The flaw is easily exploitable and, if successfully leveraged, permits complete compromise of the site, impacting confidentiality, integrity, and availability. With a CVSS vector of AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, the issue is classified as critical.

Affected Systems

The affected versions are Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0. As the vulnerability includes a scope change, other products in the Fusion Middleware stack could also be impacted under certain conditions.

Risk and Exploitability

The CVSS base score of 9.9, combined with a low exploitation effort from a low‑privileged attacker, results in a high risk. The EPSS score of <1 % indicates rare current exploitation, and the vulnerability is not yet listed in CISA’s KEV catalog. Nonetheless, an attacker with network connectivity can immediately exploit the flaw through standard HTTP traffic, elevating privileges and enabling full takeover of the affected sites.

Generated by OpenCVE AI on August 2, 2026 at 21:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Oracle patch for WebCenter Sites 12.2.1.4.0 or 14.1.2.0.0 from the 2026 CPU July update.
  • Configure firewalls and access controls to restrict HTTP/HTTPS traffic to trusted IP addresses, isolating the web center from the public internet.
  • Enable logging and continuous monitoring for anomalous authentication attempts and configuration changes on the affected servers.

Generated by OpenCVE AI on August 2, 2026 at 21:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Low-Privilege HTTP Exploit in Oracle WebCenter Sites

Tue, 28 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Remote Takeover Vulnerability in Oracle WebCenter Sites via HTTP
Weaknesses CWE-287

Mon, 27 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover Vulnerability in Oracle WebCenter Sites via HTTP
Weaknesses CWE-287

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:56:36.197Z

Reserved: 2026-07-08T15:51:40.544Z

Link: CVE-2026-60552

cve-icon Vulnrichment

Updated: 2026-07-27T11:24:34.794Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:00:07Z

Weaknesses