CVE-2026-83035
nicheUnauthenticated HTTP Takeover of Oracle WebCenter Sites (CVSS 9.8)
A critical vulnerability (CVSS 3.1 base score 9.8) in the WebCenter Sites component of Oracle Fusion Middleware allows an unauthenticated remote attacker with network access via HTTP to compromise the affected Oracle WebCenter Sites installation. The flaw is rated easily exploitable and requires no privileges or user interaction, so crafted HTTP requests sent directly to an exposed Sites deployment can trigger it. Successful attacks result in a complete takeover of Oracle WebCenter Sites, with high impacts to confidentiality, integrity, and availability — meaning an attacker could read or modify content and data or disrupt the service. Affected installations run WebCenter Sites 12.2.1.4.0 or 14.1.2.0.0, typically enterprise web content management deployments reachable over intranet or internet HTTP. As of this analysis, no public proof-of-concept is known, the CVE is not on the CISA Known Exploited Vulnerabilities list, and no in-the-wild exploitation has been confirmed.
What to do: Apply the Oracle Critical Patch Update (CPU) that resolves this CVE to WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 as a top priority — consult the latest Oracle advisory for the fixed builds. Until patched, restrict HTTP access to Sites and its admin/content-server endpoints to trusted networks (VPN or IP allow-listing) and place a WAF or reverse proxy in front to filter unauthenticated requests. Review access and application logs on these systems for anomalous unauthenticated activity that could indicate probing or exploitation attempts.
| Oracle WebCenter Sites (Oracle Fusion Middleware) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.