Junglewise Threat Intelligence

CVE-2026-61140: Oracle WebCenter Sites remote compromise and takeover

CVE-2026-61140 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites, a platform used for managing large-scale web content and digital experiences, contains a critical security flaw. An unauthorized person can remotely take full control of the system over the internet without needing any login credentials. This could lead to a total loss of data confidentiality, unauthorized modification of website content, and disruption of business operations.

Technical details

A critical vulnerability exists in the WebCenter Sites component of Oracle Fusion Middleware version 14.1.2.0.0. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. While the specific CWE is not provided in the advisory, the high CVSS score and 'takeover' description suggest a remote code execution (RCE) or complete authentication bypass. Successful exploitation results in a total compromise of confidentiality, integrity, and availability (CVSS 9.8). Users should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle WebCenter Sites 14.1.2.0.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Published in Oracle Critical Patch Update July 2026

References

Related threats