Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle WebCenter Sites allows an unauthenticated attacker with HTTP network access to compromise the application and obtain unauthorized access to critical data. The flaw permits the attacker to view all data that is normally protected by the application's confidentiality controls. The CVSS 3.1 base score of 7.5 reflects a high confidentiality impact with no requirement for privileges, user interaction, or elevated privileges, and an unmodified scope.

Affected Systems

The issue affects Oracle WebCenter Sites version 12.2.1.4.0 and 14.1.2.0. Administrators of these releases should verify that their deployments include the relevant patch set.

Risk and Exploitability

The EPSS score of less than 1% indicates that the exploitation probability is low, and the vulnerability is not listed in the CISA KEV catalog. However, the lack of privilege or user interaction requirements means that any system exposed to network traffic that can reach the WebCenter Sites HTTP endpoint is potentially vulnerable. Attackers could exploit the flaw to read sensitive content, but the impact is limited to confidentiality and does not affect integrity or availability.

Generated by OpenCVE AI on August 2, 2026 at 21:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in the July 2026 CPU for WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 to remove the vulnerability.
  • Restrict network access to WebCenter Sites endpoints to trusted IP ranges or internal networks to reduce exposure.
  • Implement web application firewall rules or intrusion detection alerts to detect and block suspicious HTTP requests targeting the vulnerable components.

Generated by OpenCVE AI on August 2, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Exposure in Oracle WebCenter Sites via HTTP

Tue, 28 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability in Oracle WebCenter Sites Allows Unauthorized Data Access
Weaknesses CWE-284

Mon, 27 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability in Oracle WebCenter Sites Allows Unauthorized Data Access
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T11:27:38.825Z

Reserved: 2026-07-08T15:51:40.544Z

Link: CVE-2026-60554

cve-icon Vulnrichment

Updated: 2026-07-27T11:26:48.971Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:00:07Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor