Junglewise Threat Intelligence

CVE-2026-46801: Oracle WebCenter Sites authentication bypass

CVE-2026-46801 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites, a platform used for managing large-scale web content and digital experiences, contains a critical security vulnerability. An unauthorized person can gain full control over the system over the internet without needing any login credentials. This could lead to a total loss of data confidentiality, unauthorized changes to website content, and disruption of services.

Technical details

A vulnerability in Oracle WebCenter Sites (component of Oracle Fusion Middleware) is classified as a missing authentication for a critical function (CWE-306). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows for a complete takeover of the Oracle WebCenter Sites instance, impacting confidentiality, integrity, and availability. The vulnerability affects supported versions 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation details.

Affected products

  • Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Security Alert published

References

Related threats