Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).
Published: 2026-08-18
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle WebCenter Sites allows an unauthenticated attacker with network access over HTTP to compromise the system. Successful exploitation can lead to unauthorized reading of critical data, as well as inserting, updating, or deleting data, and can induce a partial denial of service. The primary weakness is improper access control, as reflected in the CVSS vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L.

Affected Systems

Oracle WebCenter Sites product versions 12.2.1.4.0 and 14.1.2.0.0 are affected. No other vendors or product families are listed as impacted.

Risk and Exploitability

The vulnerability carries a CVSS 3.1 base score of 8.6, indicating high severity. The EPSS score of less than 1% indicates that exploitation probability is currently very low, and the vulnerability is not listed in the CISA KEV catalog. The CVSS vector shows a remote attack over an insecure HTTP protocol with no authentication required, meaning any network user could attempt to abuse the flaw. Because it can lead to unauthorized data access, modification, and partial service disruption, the risk remains significant for organizations running these versions.

Generated by OpenCVE AI on August 21, 2026 at 15:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebCenter Sites patch for versions 12.2.1.4.0 and 14.1.2.0.0 as released in the Oracle security alert referenced above.
  • If patching is not immediately possible, restrict HTTP access to the application by placing it behind a firewall or proxy that limits inbound traffic to trusted IP addresses.
  • Audit and harden the site’s authentication and authorization configuration, ensuring that all data access requires proper credentials and privileges.
  • Monitor logs for suspicious activity such as repeated unauthenticated requests and enforce rate limiting to mitigate potential denial of service.
  • Keep the system updated with future security releases and review Oracle’s advisories for additional mitigations.

Generated by OpenCVE AI on August 21, 2026 at 15:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access in Oracle WebCenter Sites Leads to Unauthorized Data Exposure and Service Degradation
Weaknesses CWE-862

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access in Oracle WebCenter Sites Leads to Unauthorized Data Exposure and Service Degradation
Weaknesses CWE-284
CWE-862

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:17.848Z

Reserved: 2026-07-08T15:51:55.609Z

Link: CVE-2026-61033

cve-icon Vulnrichment

Updated: 2026-08-19T12:13:09.804Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:53.107

Modified: 2026-08-20T15:08:15.620

Link: CVE-2026-61033

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T15:15:16Z

Weaknesses