Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-08-18
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker with network access to HTTP can exploit a flaw in Oracle WebCenter Sites to obtain access to critical data and to perform update, insert, or delete operations on that data. The vulnerability exposes confidentiality at a high level and a lower level of integrity impact, and it is rated CVSS 3.1 with a base score of 8.2. This indicates a serious risk that could compromise data confidentiality and allow data manipulation without proper authorization.

Affected Systems

Oracle WebCenter Sites version 12.2.1.4.0 and version 14.1.2.0.0 are vulnerable to the described flaw. Users of these releases should verify their installation version and apply any available vendor updates.

Risk and Exploitability

The known exploitation path involves sending specially crafted HTTP traffic to an unauthenticated WebCenter Sites instance. The CVSS score of 8.2 signals a high severity, while the EPSS score is not available, leaving uncertainty about current exploitation prevalence. The vulnerability is not listed in CISA’s KEV catalog, but given its authentication bypass nature and the potential for data tampering, risk remains substantial for exposed installations.

Generated by OpenCVE AI on August 19, 2026 at 00:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle WebCenter Sites patch or upgrade to a fixed release that addresses this flaw
  • Restrict HTTP access to the WebCenter Sites instance to trusted IP ranges or implement VPN or firewall rules to limit exposure
  • Ensure that all data manipulation endpoints require proper authentication and authorization checks, and verify that the site’s access controls are enforced according to the principle of least privilege

Generated by OpenCVE AI on August 19, 2026 at 00:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access Vulnerability in Oracle WebCenter Sites
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:42.303Z

Reserved: 2026-07-08T15:51:55.610Z

Link: CVE-2026-61054

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:53.807

Modified: 2026-08-18T21:16:53.807

Link: CVE-2026-61054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T00:15:13Z

Weaknesses