CVE-2026-83034
nicheUnauthenticated HTTP Data Disclosure in Oracle WebCenter Sites (CVSS 7.5)
CVE-2026-83034 is an easily exploitable vulnerability in the WebCenter Sites component of Oracle Fusion Middleware that allows an unauthenticated attacker with network access via HTTP to compromise the affected WebCenter Sites installation. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) indicates the impact is limited to confidentiality: a successful attack yields unauthorized access to critical data or complete read access to all Oracle WebCenter Sites accessible data, with no integrity or availability impact. The flaw affects supported versions 12.2.1.4.0 and 14.1.2.0.0 of WebCenter Sites. Organizations running these versions with the Sites application reachable over a network — especially internet-facing instances — are at risk of sensitive content and data exposure. As of now, the vulnerability is not in CISA's KEV catalog and no public proof-of-concept is known.
What to do: Apply the Oracle Critical Patch Update that remediates this issue to WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 as soon as it is available via My Oracle Support. Restrict network-level access to Sites endpoints (especially any internet-exposed instances) using firewalls, VPNs, or reverse proxies with authentication until patched. Review HTTP access logs for unauthenticated requests to Sites resources that could indicate probing or data harvesting attempts.
| Oracle WebCenter Sites (Oracle Fusion Middleware) | 12.2.1.4.0 |
| Oracle WebCenter Sites (Oracle Fusion Middleware) | 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.