Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L).
Published: 2026-08-18
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle WebCenter Sites allows an attacker without authentication to use HTTP requests to create, delete, or modify data stored in the application. This vulnerability arises from missing access control (CWE‑284) and can also trigger a partial denial of service. The impact is limited to the integrity and availability of the application; confidentiality is not directly impacted. The CVSS v3.1 score of 8.2 reflects high severity.

Affected Systems

Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 are affected. These versions are part of Oracle Fusion Middleware and are used to deliver web content and data management services. No other Oracle product is listed as impacted.

Risk and Exploitability

The CVSS base score of 8.2 indicates a strong impact if exploited. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, but the URL‑based attack path and lack of authentication requirements suggest a high likelihood of exploitation from the Internet or an internal network. An attacker could manipulate critical data or disrupt service without any user credentials.

Generated by OpenCVE AI on August 21, 2026 at 13:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle WebCenter Sites patch that addresses CVE-2026-61016 or upgrade to a non‑affected version.
  • Restrict inbound HTTP traffic to the WebCenter Sites servers using network segmentation, firewalls or VPNs, allowing only trusted hosts to reach the application.
  • Enforce proper authentication and role‑based access control for all data‑handling and administrative endpoints so that only authorized users can perform CRUD operations.
  • Deploy monitoring and intrusion detection that flags abnormal HTTP requests or rapid data modification patterns to detect attempts to exploit the vulnerability.

Generated by OpenCVE AI on August 21, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Modification and Partial DoS in Oracle WebCenter Sites

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:18.063Z

Reserved: 2026-07-08T15:51:55.608Z

Link: CVE-2026-61016

cve-icon Vulnrichment

Updated: 2026-08-19T12:13:13.579Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:52.247

Modified: 2026-08-20T15:08:20.910

Link: CVE-2026-61016

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:30:04Z

Weaknesses