Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper authorization bypass that allows an unauthenticated attacker who can reach Oracle WebCenter Sites over HTTP to fully compromise the system. Successful exploitation can result in takeover of the application, enabling the attacker to alter or delete data, execute arbitrary code, and disrupt availability, thereby causing complete loss of confidentiality, integrity, and availability. The weakness corresponds to CWE‑284.

Affected Systems

Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 are affected. All deployments of these versions are at risk unless a patch is applied or a newer, non‑affected release is installed.

Risk and Exploitability

The CVSS 3.1 base score of 9.8 marks the vulnerability as critical. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request to the application, and the impact scope covers the entire WebCenter Sites instance.

Generated by OpenCVE AI on August 2, 2026 at 21:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch for CVE‑2026‑60555 or upgrade to a newer patch release of Oracle WebCenter Sites
  • Restrict external network access to the WebCenter Sites instance using firewall rules or a VPN, limiting HTTP exposure to trusted IP ranges
  • Monitor web server logs and network traffic for anomalous HTTP requests that may indicate attempts to exploit the authorization bypass

Generated by OpenCVE AI on August 2, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Oracle WebCenter Sites via HTTP Enables System Compromise

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Oracle WebCenter Sites via HTTP Enables System Compromise

Mon, 27 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:56:44.052Z

Reserved: 2026-07-08T15:51:40.544Z

Link: CVE-2026-60555

cve-icon Vulnrichment

Updated: 2026-07-27T11:28:15.511Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:00:07Z

Weaknesses