ZeroHour

CVE-2026-83036

niche

Unauthenticated HTTP Takeover Flaw in Oracle WebCenter Sites 12.2.1.4.0 / 14.1.2.0.0

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

Oracle WebCenter Sites, a component of Oracle Fusion Middleware, contains an easily exploitable vulnerability in supported versions 12.2.1.4.0 and 14.1.2.0.0 that allows an unauthenticated attacker with network access via HTTP to compromise the application. The flaw requires no privileges and no user interaction, and successful exploitation can result in a complete takeover of Oracle WebCenter Sites with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 9.8, critical). Oracle's advisory does not detail the exact technical root cause (e.g., the specific endpoint or component flaw), but the attack surface is any network-reachable WebCenter Sites HTTP service running an affected version. Organizations running either supported version on-premises or in internet-facing deployments are affected. There is no known public proof of concept and the vulnerability is not on CISA's Known Exploited Vulnerabilities catalog, so exploitation status is currently none known.

What to do: Apply the Oracle Critical Patch Update (CPU) that remediates this flaw to all WebCenter Sites instances on 12.2.1.4.0 or 14.1.2.0.0. Until patched, restrict HTTP access to WebCenter Sites endpoints to trusted networks or VPN (firewall rules, WAF, or IP allowlisting) since the flaw is exploitable unauthenticated over HTTP. Review logs for anomalous unauthenticated requests to WebCenter Sites and check for signs of prior compromise such as unexpected administrative changes.

Affected
Oracle WebCenter Sites (Oracle Fusion Middleware)
Estimated exposure
niche≈ hundreds to low thousands of deployments worldwide, with likely only a few hundred internet-exposed instances — WebCenter Sites is a niche enterprise web content management product typically deployed on-premises by large organizations, and public internet-wide scans historically surface only a few hundred exposed WebCenter Sites instances, so this…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.