Executive brief
Oracle WebCenter Sites is a content management platform used to build and manage web applications and digital experiences. An attacker with low privileges and network access can exploit this vulnerability to fully compromise WebCenter Sites and potentially impact other connected systems. Successful exploitation enables complete takeover of the platform, affecting confidentiality, integrity, and availability of managed content and services.
Technical details
This is a low-privilege authentication bypass or privilege escalation vulnerability in Oracle WebCenter Sites. The vulnerability is easily exploitable and requires only network access via HTTP and a low-privileged user account; no complex preconditions or user interaction is needed. An authenticated attacker can achieve complete system compromise, potentially with scope change affecting downstream systems. The vulnerability affects WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0. Oracle has released security patches via their September 2026 Critical Patch Update.
Affected products
- Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed
- 2026-09: patched: Oracle Critical Patch Update