Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L).
Published: 2026-08-18
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle WebCenter Sites component has an authentication bypass that permits unauthenticated HTTP requests to perform privileged operations such as creating, deleting, or modifying site content. Successful exploitation could let an attacker alter critical data or remove content and also cause a partial denial of service by disrupting access to legitimate users. The flaw is identified as an improper authentication and access control weakness, allowing attackers to subvert the intended security model.

Affected Systems

Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware.

Risk and Exploitability

The flaw carries a CVSS 3.1 base score of 8.2, which denotes a high‑severity vulnerability with the ability to compromise data integrity and partially disrupt availability. Because the flaw is exploitable over HTTP without authentication, an attacker with network access can launch the attack remotely. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers would use standard HTTP requests without authentication to exploit the flaw.

Generated by OpenCVE AI on August 21, 2026 at 14:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch or upgrade that fixes the authentication bypass in WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0.
  • If a patch is not yet available, block HTTP traffic to the WebCenter Sites endpoints from all untrusted IP addresses or restrict access to a trusted administrator range using a firewall or VPN.
  • Verify that only authenticated users can perform content‑management operations and that no privileged actions can be executed by unauthenticated requests, following proper authorization controls.

Generated by OpenCVE AI on August 21, 2026 at 14:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Authentication Bypass in Oracle WebCenter Sites Enables Privileged Operations and Partial Denial of Service

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:18.291Z

Reserved: 2026-07-08T15:51:55.607Z

Link: CVE-2026-61011

cve-icon Vulnrichment

Updated: 2026-08-19T12:13:17.785Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:52.130

Modified: 2026-08-20T15:08:28.287

Link: CVE-2026-61011

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T14:15:07Z

Weaknesses