Executive brief
Oracle WebCenter Sites, a platform for managing large-scale web content and digital experiences, contains a vulnerability that could allow an unauthorized person to access or modify sensitive data. An attacker could potentially gain full control over the information stored within the system or use it as a stepping stone to impact other connected business applications. While the attack is complex to execute, it does not require a username or password and can be performed over the internet.
Technical details
This vulnerability exists in the WebCenter Sites component of Oracle Fusion Middleware. It is an unauthenticated, network-based attack via HTTP that is characterized by high attack complexity (AC:H) and a scope change (S:C), meaning an exploit can impact components beyond the immediate security scope of WebCenter Sites. Successful exploitation allows for the unauthorized creation, deletion, or modification of all accessible data, as well as complete read access to critical information. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published