Junglewise Threat Intelligence

CVE-2026-83033: Oracle WebCenter Sites privilege escalation in WebCenter Sites

CVE-2026-83033 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites is a web content management system used by enterprises to publish and manage digital content. A vulnerability in this product allows a low-privileged attacker with network access to gain complete control of the system, potentially leading to data theft, system compromise, and service disruption for organizations relying on it for content delivery.

Technical details

This is an easily exploitable vulnerability in Oracle WebCenter Sites requiring only low privileges and network-accessible HTTP access. The vulnerability allows an authenticated attacker to compromise the integrity, confidentiality, and availability of the WebCenter Sites instance. The attack requires low privilege credentials but no additional user interaction. Successful exploitation results in complete takeover of the WebCenter Sites application. Patches are expected to be available through Oracle's standard security update channels.

Affected products

  • Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats