Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-08-18
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle WebCenter Sites permits an attacker with network access to HTTP to bypass authentication and retrieve or alter data. The flaw allows unauthenticated users to read sensitive data and to perform unauthorized insert, update or delete operations. The impact includes confidentiality compromise for critical information and integrity violations, but the application itself remains available.

Affected Systems

Affected versions are Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 from Oracle Corporation. Any deployment of these releases is at risk if no mitigation has been applied.

Risk and Exploitability

The CVSS 3.1 score of 8.2 indicates a high severity with significant confidentiality impact and moderate integrity impact. Exploitation requires no credentials and is reachable over the network via HTTP, implying that an attacker can be a remote threat actor with network visibility. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, but the lack of prior exploitation does not reduce the risk posed by the exploitability score and the nature of the attack vector.

Generated by OpenCVE AI on August 19, 2026 at 00:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for WebCenter Sites to address this issue.
  • Configure the application server to enforce authentication on all endpoints and restrict HTTP access to trusted networks.
  • Review and harden database permissions so that only authorized accounts can modify critical data.

Generated by OpenCVE AI on August 19, 2026 at 00:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access Allowing Unauthorized Data Manipulation in Oracle WebCenter Sites
Weaknesses CWE-200
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:40.093Z

Reserved: 2026-07-08T15:51:55.609Z

Link: CVE-2026-61038

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:53.340

Modified: 2026-08-18T21:16:53.340

Link: CVE-2026-61038

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T00:15:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-287

    Improper Authentication