Junglewise Threat Intelligence

CVE-2026-46798: Oracle WebCenter Sites authentication bypass and system takeover

CVE-2026-46798 · Severity: critical · CVSS 10 · Published 2026-06-17

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites, a platform used by organizations to manage and deliver digital content and websites, contains a critical security flaw. An unauthorized person can use the internet to take complete control of the system without needing a username or password. This could lead to the theft of sensitive data, total service disruption, and may allow the attacker to move into other connected business systems.

Technical details

A critical vulnerability exists in the WebCenter Sites component of Oracle Fusion Middleware, specifically categorized as a missing authentication for a critical function (CWE-306). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation results in a complete takeover of the Oracle WebCenter Sites instance (Confidentiality, Integrity, and Availability impacts). Notably, the vulnerability includes a 'scope change' (S:C), meaning an attack can impact products and resources beyond the security scope of WebCenter Sites itself. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.

Affected products

  • Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle published security alert cspujun2026.html

References

Related threats