Description
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Application Takeover
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in Oracle WebCenter Sites allows an unauthenticated attacker with network access over HTTP to bypass authentication and gain full control of the application. The flaw enables a complete takeover, potentially exposing sensitive data, altering application content, and rendering the site unavailable. The impact is a critical compromise of confidentiality, integrity, and availability of the WebCenter Sites service. Based on the description, the attacker could possibly execute arbitrary code as the application, but this is inferred rather than explicitly stated by the source.

Affected Systems

The affected product is Oracle WebCenter Sites, specifically versions 12.2.1.4.0 and 14.1.2.0.0, which form part of Oracle Fusion Middleware. Systems running these versions are vulnerable if the application accepts HTTP requests from untrusted networks.

Risk and Exploitability

The CVSS 3.1 base score of 9.8 indicates critical severity. The EPSS score of less than 1% suggests a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated user sending crafted HTTP requests through a public or exposed network to a WebCenter Sites instance. Successful exploitation would result in application takeover, effectively allowing the attacker to perform any action that the web application permits, including malicious code execution, data exfiltration, or denial of service.

Generated by OpenCVE AI on September 17, 2026 at 04:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or update that addresses the authentication bypass for Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0.
  • Restrict direct HTTP access to the WebCenter Sites instance by configuring firewall rules, VPNs, or internal network segmentation so that only trusted hosts can reach the application.
  • Disable or remove any legacy authentication or support modes if available, and ensure that the authentication mechanism requires proper credentials before granting access.

Generated by OpenCVE AI on September 17, 2026 at 04:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Authentication Bypass Leading to Oracle WebCenter Sites Takeover

Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-306

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle webcenter Sites
CPEs cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Sites
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Webcenter Sites
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T22:54:38.012Z

Reserved: 2026-08-31T15:40:57.333Z

Link: CVE-2026-83036

cve-icon Vulnrichment

Updated: 2026-09-15T22:45:57.675Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-15T20:18:11.970

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83036

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T05:00:14Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function