Executive brief
Oracle WebCenter Sites, a platform used by organizations to manage and deliver digital content and websites, contains a critical security vulnerability. An unauthorized person can remotely take full control of the system over the internet without needing any login credentials. This could lead to the complete theft of sensitive data, website defacement, or a total shutdown of the service.
Technical details
A critical vulnerability exists in the WebCenter Sites component of Oracle Fusion Middleware, classified as a missing authentication for a critical function (CWE-306). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows for a complete takeover of the Oracle WebCenter Sites instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.
Affected products
- Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle published security alert cspujun2026.html