Junglewise Threat Intelligence

CVE-2026-83037: Oracle WebCenter Sites remote code execution

CVE-2026-83037 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Technologies: Oracle WebCenter Sites. Vendors: Oracle.

Executive brief

Oracle WebCenter Sites is a content management and web application platform used to build and manage enterprise websites. An unauthenticated remote attacker can exploit a vulnerability over the network to fully compromise the system, potentially gaining complete control of the website, customer data, and underlying infrastructure.

Technical details

This is a critical remote code execution vulnerability in Oracle WebCenter Sites (component: WebCenter Sites) that allows unauthenticated attackers to compromise the product via network access over HTTP. The vulnerability requires no user interaction or authentication, and affects versions 12.2.1.4.0 and 14.1.2.0.0. Successful exploitation results in complete system takeover with full confidentiality, integrity, and availability impact. The CVSS 3.1 score of 9.8 reflects the critical severity (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Patch status and mitigation details are not available in the provided advisory.

Affected products

  • Oracle WebCenter Sites 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats