ZeroHour

CVE-2026-83037

niche

Unauthenticated Takeover Flaw in Oracle WebCenter Sites (CVSS 9.8)

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83037 is a critical (CVSS 9.8) vulnerability in Oracle WebCenter Sites, a component of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.0.0. It is described by Oracle as easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction. A successful attack allows complete takeover of the Oracle WebCenter Sites installation, with high impact on confidentiality, integrity, and availability. Organizations running either affected version with the Sites application reachable over a network are exposed, particularly if the service is internet-facing. No public proof of concept is known and the flaw is not currently listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation status is none known at this time.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83037 to all WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 installations as the highest priority. Until patched, restrict network access to the Sites application so only trusted users and networks can reach it over HTTP, and avoid exposing admin interfaces to the internet. Review logs for unauthenticated HTTP requests to WebCenter Sites endpoints for signs of probing or abuse.

Affected
Oracle WebCenter Sites (Oracle Fusion Middleware)12.2.1.4.0
Oracle WebCenter Sites (Oracle Fusion Middleware)14.1.2.0.0
Estimated exposure
nicheLikely hundreds to low thousands of internet-reachable WebCenter Sites deployments, plus additional internal enterprise instances (order of magnitude:… — WebCenter Sites is a niche enterprise web content management platform typically deployed in large organizations, and public internet-wide scans have historically shown only a few hundred to low thousands of exposed instances.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.