Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Oracle WebCenter Sites allows an unauthenticated attacker with network access via HTTP to exploit an improper access control weakness (CWE‑284) and gain unauthorized access to critical data or full site data. Successful exploitation results in a high confidentiality impact while integrity and availability are not affected. The weakness permits information disclosure without proper authorization.

Affected Systems

The affected product is Oracle WebCenter Sites, part of Oracle Fusion Middleware, with vulnerable versions 12.2.1.4.0 and 14.1.2.0.0.

Risk and Exploitability

The severity is moderate to high, reflected by a CVSS base score of 7.5 with an AV:N, AC:L, PR:N, UI:N, S:U, C:H, I:N, A:N vector. The EPSS score is below 1%, indicating a low but non‑zero exploitation probability, and the vulnerability is not listed in CISA KEV. The likely attack vector is via HTTP to an unauthenticated user, requiring no credentials, which means organizations exposed to public or untrusted networks face a significant risk of data compromise.

Generated by OpenCVE AI on August 21, 2026 at 12:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch or upgrade Oracle WebCenter Sites to a version that contains the fix.
  • Use firewall rules or network segmentation to restrict HTTP access to the WebCenter Sites instance to trusted IP ranges only.
  • Disable or restrict any unused HTTP endpoints and enforce authentication or application‑level access controls as a temporary workaround.

Generated by OpenCVE AI on August 21, 2026 at 12:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Control Over Oracle WebCenter Sites Data

Wed, 19 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Control Over Oracle WebCenter Sites Data
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T19:49:17.062Z

Reserved: 2026-07-08T15:51:55.607Z

Link: CVE-2026-61007

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:51.887

Modified: 2026-08-21T16:10:02.863

Link: CVE-2026-61007

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:15:05Z

Weaknesses