CVE-2026-83036
nicheUnauthenticated HTTP Takeover Flaw in Oracle WebCenter Sites 12.2.1.4.0 / 14.1.2.0.0
Oracle WebCenter Sites, a component of Oracle Fusion Middleware, contains an easily exploitable vulnerability in supported versions 12.2.1.4.0 and 14.1.2.0.0 that allows an unauthenticated attacker with network access via HTTP to compromise the application. The flaw requires no privileges and no user interaction, and successful exploitation can result in a complete takeover of Oracle WebCenter Sites with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 9.8, critical). Oracle's advisory does not detail the exact technical root cause (e.g., the specific endpoint or component flaw), but the attack surface is any network-reachable WebCenter Sites HTTP service running an affected version. Organizations running either supported version on-premises or in internet-facing deployments are affected. There is no known public proof of concept and the vulnerability is not on CISA's Known Exploited Vulnerabilities catalog, so exploitation status is currently none known.
What to do: Apply the Oracle Critical Patch Update (CPU) that remediates this flaw to all WebCenter Sites instances on 12.2.1.4.0 or 14.1.2.0.0. Until patched, restrict HTTP access to WebCenter Sites endpoints to trusted networks or VPN (firewall rules, WAF, or IP allowlisting) since the flaw is exploitable unauthenticated over HTTP. Review logs for anomalous unauthenticated requests to WebCenter Sites and check for signs of prior compromise such as unexpected administrative changes.
| Oracle WebCenter Sites (Oracle Fusion Middleware) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.