Executive brief
Oracle WebCenter Sites, a platform used for managing large-scale web content and digital experiences, contains a security vulnerability that allows an attacker to take full control of the system. An individual with basic user access to the network can exploit this flaw to view sensitive data, modify content, or disrupt site availability. This could lead to a total compromise of the web infrastructure and loss of customer trust.
Technical details
A vulnerability in the WebCenter Sites component of Oracle Fusion Middleware (specifically versions 12.2.1.4.0 and 14.1.2.0.0) is classified as Improper Access Control (CWE-284). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. It does not require user interaction. Successful exploitation allows the attacker to compromise the confidentiality, integrity, and availability of the system, potentially leading to a complete takeover of the application. Oracle has addressed this in their June 2026 security update.
Affected products
- Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published