Description
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Services Manager. While the vulnerability is in Oracle Web Services Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Web Services Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Web Services Manager accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Web Services Security component of Oracle Web Services Manager, allowing attackers with network access via HTTP to create, delete or modify data that the product manages. The impact is a loss of confidentiality and integrity, as attackers can gain unauthorized access or alter critical data. The weakness is a form of access control failure, permitting low‑privileged users to elevate their permissions inadvertently.

Affected Systems

Oracle Web Services Manager versions 12.2.1.4.0, 14.1.2.0.0, and 14.1.2.1.0 are affected. These versions run as part of Oracle Fusion Middleware and may be deployed on various operating systems; the issue is identified by the three corresponding CPE strings specified in the CVE data.

Risk and Exploitability

The CVSS score of 9.6 indicates a critical severity. The attack vector is via network HTTP traffic and only low privilege, making the vulnerability readily exploitable. The entry is not listed in CISA KEV and its EPSS score is <1%, indicating a very low but non‑zero exploitation probability, but the high CVSS and the obvious network attack surface suggest a significant risk to systems that expose Web Services Manager to untrusted networks. Successful exploitation would give attackers unauthorized control over data held by the product and potentially affect other products that share the same data or configuration settings.

Generated by OpenCVE AI on August 21, 2026 at 14:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest patch for Oracle Web Services Manager, upgrading versions 12.2.1.4.0 or 14.1.2.0.0 to the most recent releases that contain the fix.
  • Restrict HTTP access to the Web Services Manager installation to trusted hosts or a VPN, thereby limiting exposure to attackers from untrusted networks.
  • Audit authentication and authorization configurations to ensure only privileged users can perform data modifications, and disable any unused services or interfaces that are not required for business operations.

Generated by OpenCVE AI on August 21, 2026 at 14:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Title Access Control Failure in Oracle Web Services Manager Allows Unauthorized Data Modification
Weaknesses CWE-284

Fri, 21 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Remote Data Exposure in Oracle Web Services Manager via Low-Privilege HTTP Access
Weaknesses CWE-200
CWE-284

Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:oracle:web_services_manager:14.1.2.1.0:*:*:*:*:*:*:*

Wed, 19 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Remote Data Exposure in Oracle Web Services Manager via Low-Privilege HTTP Access
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Services Manager. While the vulnerability is in Oracle Web Services Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Web Services Manager accessible data as well as unauthorized access to critical data or complete access to all Oracle Web Services Manager accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle web Services Manager
CPEs cpe:2.3:a:oracle:web_services_manager:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:web_services_manager:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle web Services Manager
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Web Services Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T16:30:01.631Z

Reserved: 2026-07-08T15:51:55.607Z

Link: CVE-2026-61001

cve-icon Vulnrichment

Updated: 2026-08-21T14:53:55.864Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:16:51.523

Modified: 2026-08-24T17:17:30.140

Link: CVE-2026-61001

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T14:45:16Z

Weaknesses