Executive brief
Oracle WebCenter Sites is a content management system used for building enterprise web portals. A low-privilege authenticated attacker with network access can exploit an unspecified vulnerability to gain complete control over the WebCenter Sites instance, potentially exposing customer content, modifying critical data, and causing service outages.
Technical details
This vulnerability in Oracle WebCenter Sites allows a low-privileged attacker with network access to exploit an unspecified flaw via HTTP, achieving complete system compromise (confidentiality, integrity, and availability impact). The attack requires valid authentication credentials but no user interaction. The vulnerability affects WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0. A patch is expected to be available through Oracle's critical patch updates.
Affected products
- Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed