ZeroHour

CVE-2026-83033

niche

Privilege Escalation to Full Takeover in Oracle WebCenter Sites

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

Oracle WebCenter Sites, a component of Oracle Fusion Middleware, contains an easily exploitable vulnerability rated CVSS 3.1 8.8 (high) affecting versions 12.2.1.4.0 and 14.1.2.0.0. A remote attacker who already holds low-privileged credentials for WebCenter Sites can trigger the flaw through a simple HTTP request to the application, with no user interaction required. Successful exploitation allows the attacker to take over the Oracle WebCenter Sites installation, with high impact on the confidentiality, integrity, and availability of the system. Organizations running either affected version — especially deployments with network-reachable instances or many low-privilege contributor accounts — are exposed. The vulnerability is not on the CISA KEV list and no public proof-of-concept is known, but the low attack complexity makes patching a priority.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83033 to all WebCenter Sites instances running 12.2.1.4.0 or 14.1.2.0.0. Restrict network/HTTP reachability of WebCenter Sites — particularly admin and content-management interfaces — to trusted users and networks, and audit low-privileged accounts for signs of misuse. Monitor authentication and application logs for anomalous activity by low-privilege users preceding configuration or privilege changes.

Affected
Oracle WebCenter Sites (Oracle Fusion Middleware)12.2.1.4.0
Oracle WebCenter Sites (Oracle Fusion Middleware)14.1.2.0.0
Estimated exposure
nichelikely hundreds to a few thousand enterprise deployments worldwide (estimate) — WebCenter Sites is a commercial enterprise web content management platform licensed mainly to large organizations and typically deployed on-premises, and no public install counts or internet-exposure scan data were available, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.