Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle WebCenter Sites allows an unauthenticated attacker who can reach the system over HTTP to compromise the entire application. Successful exploitation results in full takeover of the site, permitting the attacker to read, modify and delete data, and execute arbitrary code with application privileges. This flaw delivers complete confidentiality, integrity, and availability disruption, reflected by a CVSS 3.1 base score of 9.8.

Affected Systems

Affected versions are 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Sites, part of Oracle Fusion Middleware. The flaw applies to the WebCenter Sites component as identified by Oracle.

Risk and Exploitability

The vulnerability is easily exploitable, requiring no authentication and only standard HTTP network access. An EPSS score of < 1% indicates a very low probability of exploitation in the wild, but the high CVSS score demonstrates severe potential impact if exploited. The flaw is not listed in the CISA KEV catalog, meaning no publicly known exploit benchmarks exist yet. The CVSS vector shows that the impact covers confidentiality, integrity, and availability.

Generated by OpenCVE AI on August 21, 2026 at 15:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch released by Oracle for WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0, ensuring the vulnerability is fixed.
  • Restrict inbound network access to the WebCenter Sites instance by applying firewall rules that allow only trusted networks or enforce authentication, thereby reducing the attack surface.
  • Ensure all WebCenter Sites endpoints require authentication and review IAM policies to enforce least privilege, mitigating unauthorized access if the vulnerability is not yet patched.

Generated by OpenCVE AI on August 21, 2026 at 15:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Full Oracle WebCenter Sites Takeover
Weaknesses CWE-287

Fri, 21 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Full Oracle WebCenter Sites Takeover
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T03:56:59.723Z

Reserved: 2026-07-08T15:51:55.608Z

Link: CVE-2026-61018

cve-icon Vulnrichment

Updated: 2026-08-20T19:31:52.333Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:52.480

Modified: 2026-08-21T16:08:16.940

Link: CVE-2026-61018

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T15:15:16Z

Weaknesses