ZeroHour

CVE-2026-83035

niche

Unauthenticated HTTP Takeover of Oracle WebCenter Sites (CVSS 9.8)

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

A critical vulnerability (CVSS 3.1 base score 9.8) in the WebCenter Sites component of Oracle Fusion Middleware allows an unauthenticated remote attacker with network access via HTTP to compromise the affected Oracle WebCenter Sites installation. The flaw is rated easily exploitable and requires no privileges or user interaction, so crafted HTTP requests sent directly to an exposed Sites deployment can trigger it. Successful attacks result in a complete takeover of Oracle WebCenter Sites, with high impacts to confidentiality, integrity, and availability — meaning an attacker could read or modify content and data or disrupt the service. Affected installations run WebCenter Sites 12.2.1.4.0 or 14.1.2.0.0, typically enterprise web content management deployments reachable over intranet or internet HTTP. As of this analysis, no public proof-of-concept is known, the CVE is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been confirmed.

What to do: Apply the Oracle Critical Patch Update (CPU) that resolves this CVE to WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 as a top priority — consult the latest Oracle advisory for the fixed builds. Until patched, restrict HTTP access to Sites and its admin/content-server endpoints to trusted networks (VPN or IP allow-listing) and place a WAF or reverse proxy in front to filter unauthenticated requests. Review access and application logs on these systems for anomalous unauthenticated activity that could indicate probing or exploitation attempts.

Affected
Oracle WebCenter Sites (Oracle Fusion Middleware)
Estimated exposure
niche≈ hundreds to low thousands of internet-reachable installs; total deployments (internal plus external) likely in the low thousands — Oracle WebCenter Sites is a niche enterprise web content management platform, and public internet scans typically show only hundreds to low thousands of exposed Sites/content-server endpoints, with most deployments being intranet-facing.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.