Junglewise Threat Intelligence

CVE-2026-46799: Oracle WebCenter Sites authentication bypass and system takeover

CVE-2026-46799 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites, a platform used by organizations to manage and deliver digital content and websites, contains a critical security vulnerability. An unauthorized person can remotely take full control of the system over the internet without needing any login credentials. This could lead to the complete theft of sensitive data, website defacement, or a total shutdown of the service.

Technical details

A critical vulnerability exists in the WebCenter Sites component of Oracle Fusion Middleware, classified as a missing authentication for a critical function (CWE-306). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows for a complete takeover of the Oracle WebCenter Sites instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle published security alert cspujun2026.html

References

Related threats