Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Easily exploitable vulnerability in Oracle WebCenter Sites allows an attacker with low privileges and network access via HTTP to compromise the application. Successful exploitation results in full takeover, giving the attacker full confidentiality, integrity, and availability control over the affected instance.

Affected Systems

Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The flaw is present in the Fusion Middleware component WebCenter Sites core product.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 indicates a high severity. The attack vector is inferred to be over HTTP, with low assurance and no required user interaction. No EPSS score is available and the vulnerability is not listed in CISA KEV, suggesting limited known exploitation at this time. Because the attacker needs only local or remote network access and can elevate to full takeover, the risk to systems with exposed WebCenter Sites is significant.

Generated by OpenCVE AI on August 19, 2026 at 00:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Oracle WebCenter Sites security patch for versions 12.2.1.4.0 and 14.1.2.0.0 that addresses the unauthorized access flaw.
  • Restrict HTTP access to the WebCenter Sites installation via network segmentation or firewall rules, limiting exposure to trusted hosts.
  • Enforce strict authentication and authorization checks in WebCenter Sites, ensuring that only privileged users can access administrative functions.

Generated by OpenCVE AI on August 19, 2026 at 00:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Oracle WebCenter Sites Remote Takeover via HTTP by Low-Privileged Attacker
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:41.258Z

Reserved: 2026-07-08T15:51:55.609Z

Link: CVE-2026-61042

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:53.570

Modified: 2026-08-18T21:16:53.570

Link: CVE-2026-61042

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T00:15:13Z

Weaknesses