Executive brief
Oracle WebCenter Sites, a platform used for managing large-scale web content and digital experiences, contains a critical security flaw. An unauthorized person can gain full control over the system over the internet without needing a password or any user interaction. This could lead to the complete theft of sensitive data, a total service shutdown, or the use of the system to attack other parts of the corporate network.
Technical details
This vulnerability is classified as a missing authentication for a critical function (CWE-306) within the WebCenter Sites component of Oracle Fusion Middleware. It is remotely exploitable via HTTP without authentication, requiring low complexity and no user interaction. The flaw is particularly severe because it involves a 'scope change' (S:C), meaning a successful exploit can allow an attacker to move beyond the WebCenter Sites environment to impact other integrated products or the underlying infrastructure. Successful exploitation results in a complete takeover of the affected instance. Affected versions include 12.2.1.4.0 and 14.1.2.0.0.
Affected products
- Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle security alert published