Executive brief
Oracle WebCenter Sites, a content management platform for building and managing large-scale websites, contains a critical security vulnerability. An unauthenticated attacker can exploit this over the network to gain full access to sensitive data or modify and delete critical information. This could lead to a complete compromise of the website's content and the exposure of private customer or corporate data.
Technical details
A vulnerability in the WebCenter Sites component of Oracle Fusion Middleware (specifically versions 12.2.1.4.0 and 14.1.2.0.0) is classified as an improper access control issue (CWE-284). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. An attacker can achieve high confidentiality and integrity impacts, allowing for the unauthorized creation, deletion, or modification of critical data, as well as complete access to all data managed by the WebCenter Sites instance. The vulnerability does not impact availability according to the CVSS vector. Users should refer to the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD record published