Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle WebCenter Sites permits an unauthenticated attacker with network access via HTTP to compromise the application. Successful exploitation requires the involvement of an unrelated user to provide input, after which the attacker can gain unauthorized access to critical data or complete control over all data accessible through the site. The flaw results in a confidentiality breach but does not impact integrity or availability.

Affected Systems

Affected are Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0, both part of Oracle Fusion Middleware.

Risk and Exploitability

The CVSS v3.1 base score of 6.5 reflects a medium severity vulnerability with a high confidentiality impact. The EPSS score indicates less than 1 % probability that it will be exploited in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is network via HTTP and necessitates human interaction from a person other than the attacker, which reduces the likelihood of automated exploitation but still presents a risk to organizations that expose WebCenter Sites to the Internet.

Generated by OpenCVE AI on August 4, 2026 at 03:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest patch for Oracle WebCenter Sites from Oracle’s CPU for the affected versions.
  • If a patch cannot be applied immediately, consider disabling external HTTP access to the WebCenter Sites instance or placing it behind a web application firewall until the issue is resolved.
  • Configure the environment to enforce multi‑factor authentication for all users accessing the WebCenter Sites administrative interface so that no unauthenticated access is permitted.

Generated by OpenCVE AI on August 4, 2026 at 03:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated WebCenter Sites HTTP Interaction Allows Critical Data Compromise

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated WebCenter Sites HTTP Interaction Allows Critical Data Compromise

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306

Mon, 27 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Exposure in Oracle WebCenter Sites via Human Interaction
Weaknesses CWE-200
CWE-287

Mon, 27 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Exposure in Oracle WebCenter Sites via Human Interaction
Weaknesses CWE-200
CWE-287

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T14:46:54.566Z

Reserved: 2026-07-08T15:51:40.544Z

Link: CVE-2026-60557

cve-icon Vulnrichment

Updated: 2026-07-27T11:34:01.248Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function