Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Oracle WebCenter Sites allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation grants unauthorized access to critical data or full access to all site data, representing a high confidentiality impact. The weakness can be classified as an improper access control issue, allowing information disclosure without proper authorization. CVSS 3.1 score is 7.5 with AV:N, AC:L, PR:N, UI:N, S:U, C:H, I:N, A:N.

Affected Systems

The affected product is Oracle WebCenter Sites, part of Oracle Fusion Middleware, version 12.2.1.4.0 and 14.1.2.0.0.

Risk and Exploitability

The severity is moderate to high with a CVSS base score of 7.5. EPSS information is not available, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is via HTTP to an unauthenticated user; the attacker does not need any credentials or privileged access. Given the network exposure, the exploitation risk is significant for organizations operating the vulnerable instances.

Generated by OpenCVE AI on August 19, 2026 at 00:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch or upgrade Oracle WebCenter Sites to a version that contains the fix.
  • Use firewall rules or network segmentation to restrict HTTP access to the WebCenter Sites instance to trusted IP ranges only.
  • Disable or restrict any unused HTTP endpoints and enforce authentication or application‑level access controls as a temporary workaround.

Generated by OpenCVE AI on August 19, 2026 at 00:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Control Over Oracle WebCenter Sites Data
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:33.588Z

Reserved: 2026-07-08T15:51:55.607Z

Link: CVE-2026-61007

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:51.887

Modified: 2026-08-18T21:16:51.887

Link: CVE-2026-61007

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T00:30:04Z

Weaknesses