Executive brief
Oracle WebCenter Sites, a platform used by organizations to manage and deliver digital content and websites, contains a critical security flaw. An unauthorized person can use the internet to take complete control of the system without needing a username or password. This could lead to the theft of sensitive data, total service disruption, and may allow the attacker to move into other connected business systems.
Technical details
A critical vulnerability exists in the WebCenter Sites component of Oracle Fusion Middleware, specifically categorized as a missing authentication for a critical function (CWE-306). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation results in a complete takeover of the Oracle WebCenter Sites instance (Confidentiality, Integrity, and Availability impacts). Notably, the vulnerability includes a 'scope change' (S:C), meaning an attack can impact products and resources beyond the security scope of WebCenter Sites itself. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.
Affected products
- Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle published security alert cspujun2026.html