Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).
Published: 2026-08-18
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle WebCenter Sites allows an unauthenticated attacker with network access over HTTP to compromise the system. Successful exploitation can lead to unauthorized reading of critical data, as well as inserting, updating, or deleting data, and can induce a partial denial of service. The primary weakness is improper access control, as reflected in the CVSS vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L.

Affected Systems

Oracle WebCenter Sites product versions 12.2.1.4.0 and 14.1.2.0.0 are affected. No other vendors or product families are listed as impacted.

Risk and Exploitability

The vulnerability carries a CVSS 3.1 base score of 8.6, indicating high severity. EPSS information is not available, and the issue is not listed in the CISA KEV catalog. The vector indicates remote exploitation over an insecure network protocol, and the lack of authentication requirement means any network user could attempt to abuse the flaw. Given the potential for both data compromise and service interruption, the risk is significant for organizations running these software versions.

Generated by OpenCVE AI on August 19, 2026 at 00:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebCenter Sites patch for versions 12.2.1.4.0 and 14.1.2.0.0 as released in the Oracle security alert referenced above.
  • If patching is not immediately possible, restrict HTTP access to the application by placing it behind a firewall or proxy that limits inbound traffic to trusted IP addresses.
  • Audit and harden the site’s authentication and authorization configuration, ensuring that all data access requires proper credentials and privileges.
  • Monitor logs for suspicious activity such as repeated unauthenticated requests and enforce rate limiting to mitigate potential denial of service.
  • Keep the system updated with future security releases and review Oracle’s advisories for additional mitigations.

Generated by OpenCVE AI on August 19, 2026 at 00:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access in Oracle WebCenter Sites Leads to Unauthorized Data Exposure and Service Degradation
Weaknesses CWE-284
CWE-862

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:38.998Z

Reserved: 2026-07-08T15:51:55.609Z

Link: CVE-2026-61033

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:53.107

Modified: 2026-08-18T21:16:53.107

Link: CVE-2026-61033

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T00:15:13Z

Weaknesses