Executive brief
Oracle WebCenter Sites is a content management platform used to publish and manage web content. An unauthenticated attacker with network access can exploit an easily exploitable vulnerability to gain unauthorized access to all critical data stored in WebCenter Sites, potentially exposing sensitive business content and customer information without requiring any login credentials.
Technical details
This unauthenticated vulnerability in Oracle WebCenter Sites allows an attacker with network access via HTTP to bypass authentication controls and access confidential data. The vulnerability affects supported versions 12.2.1.4.0 and 14.1.2.0.0. Successful exploitation grants complete unauthorized access to all data accessible through the WebCenter Sites platform, with no user interaction or special privileges required. The attack vector is network-based with low attack complexity, making exploitation straightforward.
Affected products
- Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed