Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle WebCenter Sites enables an unauthenticated attacker who can reach the system over HTTP to compromise the entire application. Successful exploitation results in full takeover of the site, allowing the attacker to read, modify, delete data, and execute arbitrary code with the privileges of the application. This flaw delivers complete confidentiality, integrity, and availability disruption, reflected by a CVSS 3.1 base score of 9.8.

Affected Systems

Affected versions are 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Sites, part of Oracle Fusion Middleware. The flaw applies to the WebCenter Sites component as identified by Oracle.

Risk and Exploitability

The vulnerability is easily exploitable, with no authentication required and only standard network access to HTTP ports. The current EPSS score is not available, but the high CVSS score and lack of upstream mitigations underline a severe risk. The flaw is not listed in CISA KEV, so no public exploit benchmarks exist yet. The CVSS vector indicates that an attacker can achieve full confidentiality, integrity, and availability impact through remote code execution.

Generated by OpenCVE AI on August 19, 2026 at 00:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch released by Oracle for WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0, ensuring the vulnerability is fixed.
  • Restrict inbound network access to the WebCenter Sites instance by applying firewall rules that allow only trusted networks or enforce authentication, thereby reducing the attack surface.
  • Ensure all WebCenter Sites endpoints require authentication and review IAM policies to enforce least privilege, mitigating unauthorized access if the vulnerability is not yet patched.

Generated by OpenCVE AI on August 19, 2026 at 00:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Full Oracle WebCenter Sites Takeover
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:36.163Z

Reserved: 2026-07-08T15:51:55.608Z

Link: CVE-2026-61018

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:52.480

Modified: 2026-08-18T21:16:52.480

Link: CVE-2026-61018

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T00:15:13Z

Weaknesses