Executive brief
Oracle WebCenter Sites is a content management system used to build and manage web properties within enterprise organizations. This vulnerability allows an unauthenticated attacker to remotely compromise the system via network access, resulting in complete takeover including unauthorized access to all content, ability to modify or delete data, and service disruption.
Technical details
This is a remote code execution vulnerability in Oracle WebCenter Sites that requires no authentication and can be triggered via HTTP requests from the network. The vulnerability has a CVSS score of 9.8, indicating critical severity with high impact across confidentiality, integrity, and availability. Exploitation is straightforward (low complexity) and can be executed by unauthenticated attackers with only network access, allowing complete system compromise and takeover.
Affected products
- Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed