Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle WebCenter Sites version 14.1.2.0.0 permits an unauthenticated attacker with network access over HTTP to fully compromise the application. The vulnerability stems from missing or broken authorization and authentication controls, allowing arbitrary code execution and takeover of the site. This impacts confidentiality, integrity, and availability, and is classified as CWE-284 and CWE-306.

Affected Systems

Oracle WebCenter Sites, part of Oracle Fusion Middleware, version 14.1.2.0.0. All installations that expose the WebCenter Sites HTTP interface to a network without requiring prior user authentication are affected.

Risk and Exploitability

The CVSS base score of 9.8 reflects a critical severity. The EPSS score of less than 1% indicates that, in the current landscape, exploitation in the wild is infrequent, yet the vulnerability remains highly dangerous if discovered. It is not listed in the CISA KEV catalog. Exploitation requires only network connectivity to the HTTP endpoint and does not require credentials, meaning any publicly exposed instance could be targeted.

Generated by OpenCVE AI on August 4, 2026 at 01:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch for CVE-2026-61140 issued in the July 2026 CPU.
  • Restrict external HTTP access to the WebCenter Sites instance using firewall rules or VPN tunnels until the patch is applied.
  • Enable and monitor detailed logging for all HTTP requests to detect unauthenticated activity.

Generated by OpenCVE AI on August 4, 2026 at 01:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unattended Remote Code Execution via HTTP in Oracle WebCenter Sites

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unattended Remote Code Execution via HTTP in Oracle WebCenter Sites

Tue, 28 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle WebCenter Sites 14.1.2.0.0 via HTTP

Fri, 24 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle WebCenter Sites 14.1.2.0.0 via HTTP

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:56:46.234Z

Reserved: 2026-07-08T15:51:55.616Z

Link: CVE-2026-61140

cve-icon Vulnrichment

Updated: 2026-07-23T18:44:44.531Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:45:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function