Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The reported flaw within Oracle WebCenter Sites permits a low‑privileged attacker who can reach the application over HTTP to exercise control over the platform. The vulnerability stems from insufficient authentication and authorization controls that allow the attacker to access administration functions. Successful exploitation results in full site takeover, compromising all data stored within the system and disrupting public service.

Affected Systems

Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 are affected. These versions are part of the Oracle Fusion Middleware stack and are commonly deployed in intranet and internet facing web portals.

Risk and Exploitability

The CVSS v3.1 base score of 8.8 reflects high confidentiality, integrity and availability impact. The EPSS score is not available, but the vulnerability is described as easily exploitable and requires only network access over HTTP. It is not listed in the CISA KEV catalog at present. The attack path is straightforward: a remote party sends crafted HTTP requests to the vulnerable module, gains administrative access, and can then control the entire site. No additional user interaction is required beyond the initial request.

Generated by OpenCVE AI on August 19, 2026 at 00:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official vendor patch or upgrade to a fixed release of Oracle WebCenter Sites that includes the remediation.
  • Limit exposure of the WebCenter Sites instance by placing it behind a VPN or restricting inbound HTTP traffic to trusted IP ranges.
  • Enable and monitor audit logging for administration actions to detect unauthorized activity promptly.

Generated by OpenCVE AI on August 19, 2026 at 00:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Exploitation Allowing Site Takeover in Oracle WebCenter Sites
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:37.282Z

Reserved: 2026-07-08T15:51:55.608Z

Link: CVE-2026-61022

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:52.743

Modified: 2026-08-18T21:16:52.743

Link: CVE-2026-61022

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T00:15:13Z

Weaknesses