Executive brief
Oracle WebCenter Sites, a platform used for managing large-scale web content and customer experiences, contains a high-severity vulnerability. An unauthenticated attacker could exploit this flaw over the network to gain full control of the system. A successful attack could lead to a complete takeover of the site, resulting in the theft of sensitive data or a total service outage.
Technical details
A vulnerability in the WebCenter Sites component of Oracle Fusion Middleware allows an unauthenticated attacker with network access via HTTP to compromise the application. While the vulnerability is classified as difficult to exploit (Attack Complexity: High), a successful exploit results in a complete compromise of confidentiality, integrity, and availability. The flaw affects versions 12.2.1.4.0 and 14.1.2.0.0. Attackers can achieve a full system takeover without prior authentication or user interaction. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published