Junglewise Threat Intelligence

CVE-2026-83031: Oracle WebCenter Sites privilege escalation via HTTP

CVE-2026-83031 · Severity: critical · CVSS 9.9 · Published 2026-09-15

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites is a content management platform used to build and manage web applications and digital experiences. An attacker with low privileges and network access can exploit this vulnerability to fully compromise WebCenter Sites and potentially impact other connected systems. Successful exploitation enables complete takeover of the platform, affecting confidentiality, integrity, and availability of managed content and services.

Technical details

This is a low-privilege authentication bypass or privilege escalation vulnerability in Oracle WebCenter Sites. The vulnerability is easily exploitable and requires only network access via HTTP and a low-privileged user account; no complex preconditions or user interaction is needed. An authenticated attacker can achieve complete system compromise, potentially with scope change affecting downstream systems. The vulnerability affects WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0. Oracle has released security patches via their September 2026 Critical Patch Update.

Affected products

  • Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed
  • 2026-09: patched: Oracle Critical Patch Update

References

Related threats