ZeroHour

CVE-2026-83031

moderate

Privilege Escalation to Full Takeover in Oracle WebCenter Sites (CVSS 9.9)

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

Oracle WebCenter Sites, a component of Oracle Fusion Middleware, contains an easily exploitable flaw that allows a low-privileged authenticated attacker with network access via HTTP to compromise the product and achieve a complete takeover of the WebCenter Sites installation. The vulnerability carries a CVSS 3.1 base score of 9.9 with a scope change, meaning successful attacks on WebCenter Sites can significantly impact additional products beyond the initially affected component. Successful exploitation results in high impact to the confidentiality, integrity, and availability of the compromised system. Affected deployments are Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0. There is no known public proof-of-concept and no evidence of in-the-wild exploitation; the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83031 to WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 as the highest priority. Until patched, restrict HTTP access to WebCenter Sites (especially administrative and content-management interfaces) via VPN or IP allowlisting, enforce least privilege on contributor accounts, and review authentication and audit logs for anomalous activity by low-privileged users. Because the vulnerability has a scope change, also verify patch levels and inspect logs on adjacent Fusion Middleware products that share the same infrastructure.

Affected
Oracle WebCenter Sites (Oracle Fusion Middleware)
Estimated exposure
moderateLikely on the order of a few thousand internet-reachable WebCenter Sites instances worldwide; total enterprise deployments unknown — WebCenter Sites is a high-end enterprise web content management product with a limited customer base, and public internet scan services have historically shown only low-thousands of exposed WebCenter Sites endpoints, with most deployments…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.