Executive brief
Oracle WebCenter Sites, a platform used for managing large-scale web content and digital experiences, contains a critical security flaw. An unauthorized person can remotely take full control of the system over the internet without needing a username or password. This could lead to the complete theft of sensitive data, modification of website content, or a total shutdown of the service.
Technical details
A critical vulnerability exists in the WebCenter Sites component of Oracle Fusion Middleware, specifically affecting versions 12.2.1.4.0 and 14.1.2.0.0. The flaw is categorized as a missing authentication for a critical function (CWE-306), allowing an unauthenticated attacker with network access via HTTP to bypass security controls. This is an easily exploitable vulnerability that requires no user interaction. Successful exploitation results in a complete takeover of the Oracle WebCenter Sites instance, impacting confidentiality, integrity, and availability. Oracle has addressed this in their June 2026 security alerts.
Affected products
- Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory