Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).
Published: 2026-08-18
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 contain a flaw that allows an unauthenticated attacker with HTTP network access to read, insert, update, or delete site data and trigger a partial denial of service. The vulnerability is exploitable through a simple HTTP request and violates the security principle of Improper Access Control (CWE‑284). Successful exploitation grants the attacker unauthorized access to critical data and the ability to compromise confidentiality, integrity, and availability of all data exposed by the WebCenter Sites instance.

Affected Systems

Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0, components of Oracle Fusion Middleware, are affected. These releases are commonly deployed in enterprise content and site‑management environments, often exposed to the Internet or internal corporate networks.

Risk and Exploitability

The CVSS v3.1 base score of 8.6 indicates high severity, with high confidentiality impact and lower integrity and availability impact. The EPSS score of less than 1% shows a very low current exploitation probability. This vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based, requiring only unauthenticated HTTP access, which makes the potential for real‑world exploitation significant if the issue is left unmitigated.

Generated by OpenCVE AI on August 21, 2026 at 16:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s security patch for WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 or upgrade to a non‑affected release
  • Restrict inbound HTTP/HTTPS traffic to the WebCenter Sites instance by configuring firewalls or IP whitelists to limit exposure to trusted networks
  • Enable application‑level logging and implement monitoring to detect anomalous read/write or denial‑of‑service activity
  • Deploy a web application firewall or secure API gateway to block malicious request patterns

Generated by OpenCVE AI on August 21, 2026 at 16:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access and Partial Denial of Service in Oracle WebCenter Sites

Fri, 21 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit for Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0
Weaknesses CWE-287
CWE-400

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit for Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0
Weaknesses CWE-287
CWE-400

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:17.647Z

Reserved: 2026-07-08T15:51:55.609Z

Link: CVE-2026-61045

cve-icon Vulnrichment

Updated: 2026-08-19T12:13:06.866Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:53.690

Modified: 2026-08-20T15:08:10.620

Link: CVE-2026-61045

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T16:15:03Z

Weaknesses