Junglewise Threat Intelligence

CVE-2026-46797: Oracle WebCenter Sites improper access control

CVE-2026-46797 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites, a platform used by organizations to manage and deliver digital content and websites, contains a critical security vulnerability. An unauthorized person can remotely take full control of the system over the internet without needing a username or password. This could lead to the complete theft of sensitive data, modification of website content, or a total shutdown of the service.

Technical details

A critical vulnerability exists in the WebCenter Sites component of Oracle Fusion Middleware, specifically affecting versions 12.2.1.4.0 and 14.1.2.0.0. The flaw is categorized as an improper access control issue (CWE-284) that is easily exploitable. An unauthenticated attacker can exploit this vulnerability remotely over HTTP without any user interaction. Successful exploitation grants the attacker full control over the Oracle WebCenter Sites instance, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats