Junglewise Threat Intelligence

CVE-2026-83035: Oracle WebCenter Sites remote code execution

CVE-2026-83035 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites is a content management system used to build and manage web properties within enterprise organizations. This vulnerability allows an unauthenticated attacker to remotely compromise the system via network access, resulting in complete takeover including unauthorized access to all content, ability to modify or delete data, and service disruption.

Technical details

This is a remote code execution vulnerability in Oracle WebCenter Sites that requires no authentication and can be triggered via HTTP requests from the network. The vulnerability has a CVSS score of 9.8, indicating critical severity with high impact across confidentiality, integrity, and availability. Exploitation is straightforward (low complexity) and can be executed by unauthenticated attackers with only network access, allowing complete system compromise and takeover.

Affected products

  • Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats