Executive brief
Oracle WebCenter Sites is a web content management system used by enterprises to publish and manage digital content. A vulnerability in this product allows a low-privileged attacker with network access to gain complete control of the system, potentially leading to data theft, system compromise, and service disruption for organizations relying on it for content delivery.
Technical details
This is an easily exploitable vulnerability in Oracle WebCenter Sites requiring only low privileges and network-accessible HTTP access. The vulnerability allows an authenticated attacker to compromise the integrity, confidentiality, and availability of the WebCenter Sites instance. The attack requires low privilege credentials but no additional user interaction. Successful exploitation results in complete takeover of the WebCenter Sites application. Patches are expected to be available through Oracle's standard security update channels.
Affected products
- Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed