Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Remote Access to Confidential Data
Action: Immediate Patch
AI Analysis

Impact

Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0 contain an access‑control weakness that lets an unauthenticated attacker bypass authentication and read any data exposed by the application. The flaw, identified as CWE‑284, enables full read access to all content managed by the site, compromising confidentiality while leaving integrity and availability unaffected.

Affected Systems

The vulnerability impacts Oracle WebCenter Sites under the Oracle Fusion Middleware umbrella. Specifically, the 12.2.1.4.0 release and the 14.1.2.0.0 release are affected. Both versions are accessible through regular HTTP endpoints, and the weakness can be exercised on any hosted instance of the product.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 indicates high risk, driven by a network attack vector that requires low effort and no special privileges. The EPSS score of less than 1% indicates a very low probability of current exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is unauthenticated network access over HTTP; an adversary can exploit the flaw from any position on the network that can reach the WebCenter Sites instance, obtaining unrestricted read access to confidential data.

Generated by OpenCVE AI on September 17, 2026 at 04:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 as documented in the official security alert.
  • Enforce HTTPS for all WebCenter Sites traffic to eliminate the vulnerable HTTP path.
  • Restrict inbound access to the WebCenter Sites application by whitelisting trusted IP ranges and implementing firewall rules to limit exposure.

Generated by OpenCVE AI on September 17, 2026 at 04:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability in Oracle WebCenter Sites

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:25:19.348Z

Reserved: 2026-08-31T15:40:57.333Z

Link: CVE-2026-83034

cve-icon Vulnrichment

Updated: 2026-09-16T15:56:40.917Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-15T20:18:11.733

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83034

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T05:00:14Z

Weaknesses