Executive brief
Oracle WebCenter Sites, a platform used for managing and delivering digital experiences and content, contains a high-severity vulnerability. An unauthenticated attacker can exploit this over the network to gain unauthorized access to sensitive corporate data. This could lead to a significant breach of confidential information and potentially impact other integrated business systems.
Technical details
This vulnerability exists in the WebCenter Sites component of Oracle Fusion Middleware. It is classified as an unauthenticated, network-based attack vector via HTTP (AV:N/AC:L/PR:N/UI:N). The flaw is characterized by a 'Scope Change' (S:C), meaning a successful exploit can impact resources beyond the security scope of WebCenter Sites itself. The primary impact is a total loss of confidentiality (C:H) for all accessible data within the component. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation.
Affected products
- Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD