Junglewise Threat Intelligence

CVE-2026-46796: Oracle WebCenter Sites open redirect and system takeover

CVE-2026-46796 · Severity: high · CVSS 8 · Published 2026-06-17

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites, a platform used for managing and delivering digital experiences, contains a security vulnerability that could allow an attacker to take full control of the system. To succeed, an attacker needs a low-level user account and must trick a legitimate user into performing a specific action, such as clicking a malicious link. If exploited, this could lead to the theft of sensitive data, unauthorized modification of website content, or a total service outage.

Technical details

A vulnerability in the WebCenter Sites component of Oracle Fusion Middleware (specifically versions 12.2.1.4.0 and 14.1.2.0.0) is classified as an Open Redirect (CWE-601). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. While the primary weakness is an open redirect, the impact is rated as high (CVSS 8.0) because successful exploitation, which requires interaction from a victim user, can result in a complete takeover of the Oracle WebCenter Sites environment. This implies the redirect may be used in a chain to facilitate credential theft or session hijacking. Users should refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats