Junglewise Threat Intelligence

CVE-2026-83036: Oracle WebCenter Sites unauthenticated remote code execution

CVE-2026-83036 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites is a content management and web publishing platform used by enterprises to manage digital content and customer-facing websites. This vulnerability allows an unauthenticated attacker to remotely gain complete control over the system via HTTP, compromising all confidentiality, integrity, and availability of the platform and its data.

Technical details

This is an unauthenticated remote code execution vulnerability in Oracle WebCenter Sites (components: WebCenter Sites). The vulnerability is easily exploitable and requires no authentication, user interaction, or complex preconditions—only network access via HTTP. Attackers can achieve complete system compromise with high confidentiality, integrity, and availability impact. Affected versions include 12.2.1.4.0 and 14.1.2.0.0. Patches are expected from Oracle.

Affected products

  • Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed: CVE-2026-83036 published

References

Related threats