ZeroHour

CVE-2026-83032

moderate

Low-Privilege Account Takeover Flaw in Oracle WebCenter Sites

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

Oracle WebCenter Sites, a component of Oracle Fusion Middleware, contains an easily exploitable vulnerability in versions 12.2.1.4.0 and 14.1.2.0.0 that allows a low-privileged authenticated attacker with network access via HTTP to compromise the entire WebCenter Sites installation. Successful exploitation results in a full takeover of the product, with high impact on the confidentiality, integrity, and availability of managed content and the platform itself (CVSS 3.1 base score 8.8). Any organization running one of the two affected supported versions and exposing the product over a network is at risk, with the attack requiring only a valid low-privilege account rather than administrative credentials. No public proof-of-concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation is not currently observed in the wild. Patches are delivered through Oracle's Critical Patch Update program.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83032 to any WebCenter Sites instance running 12.2.1.4.0 or 14.1.2.0.0, as Oracle distributes fixes via CPU rather than standalone version bumps. Until patched, restrict HTTP/HTTPS access to WebCenter Sites (especially authoring and admin interfaces) via network segmentation or VPN-only exposure, and audit low-privileged accounts for suspicious activity or unexpected privilege changes.

Affected
Oracle WebCenter Sites (Oracle Fusion Middleware)12.2.1.4.0
Oracle WebCenter Sites (Oracle Fusion Middleware)14.1.2.0.0
Estimated exposure
moderate≈ low thousands of enterprise installations (hundreds to low thousands internet-reachable), clearly an estimate — WebCenter Sites is a niche, on-premises enterprise web content management platform typically deployed by large organizations, and internet-wide scans of its login endpoints historically show only low-thousands of exposed instances; Oracle…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.