Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle WebCenter Sites enables a low‑privileged attacker with network reachability through HTTP to compromise the application, potentially taking full control. The exploit impacts confidentiality, integrity, and availability, granting the attacker the same rights as the application itself.

Affected Systems

Affected products are Oracle WebCenter Sites within Oracle Fusion Middleware, specifically the 12.2.1.4.0 and 14.1.2.0.0 releases. The advisory lists these releases as vulnerable, and no later versions are mentioned as fixed. All installations running these versions and exposed over HTTP are potentially at risk.

Risk and Exploitability

This is a high‑severity vulnerability with a CVSS 3.1 base score of 8.8, indicating a high likelihood of successful exploitation using network access and low privilege. The EPSS score is not available, but the vulnerability is listed in Oracle’s advisory and is not yet in the CISA KEV catalog. The likely attack vector is remote via HTTP, and the weakness permits a complete takeover of the target instance.

Generated by OpenCVE AI on August 19, 2026 at 00:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle WebCenter Sites security patch corresponding to versions 12.2.1.4.0 and 14.1.2.0.0 as detailed in the official advisory.
  • If patch deployment cannot be performed immediately, restrict HTTP access to the WebCenter Sites instance to trusted IP ranges and enforce strict authentication and least‑privilege principles.
  • Disable or restrict any HTTP endpoints that are not required for normal operation and enforce HTTPS to prevent eavesdropping and man‑in‑the‑middle attacks.

Generated by OpenCVE AI on August 19, 2026 at 00:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Oracle WebCenter Sites remote takeover via HTTP exploitation
Weaknesses CWE-264
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:40.652Z

Reserved: 2026-07-08T15:51:55.609Z

Link: CVE-2026-61040

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:53.457

Modified: 2026-08-18T21:16:53.457

Link: CVE-2026-61040

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T00:15:13Z

Weaknesses