Impact
A flaw in Oracle WebCenter Sites allows an unauthenticated attacker with network access to send HTTP requests that compromise the application. The vulnerability can result in a takeover of the WebCenter Sites environment, causing loss of confidentiality, integrity, and availability. The weakness is an example of improper authentication (CWE‑287).
Affected Systems
Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The issue exists in the Fusion Middleware component WebCenter Sites as documented in Oracle’s CPU Jul 2026 advisory.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates high severity. The EPSS score of less than 1% shows a very low likelihood of exploitation at present. The flaw is not listed in CISA’s KEV catalog. Attack originates over the network via HTTP and does not require authentication, enabling an attacker to compromise the application entirely once the exploit is successful.
OpenCVE Enrichment