Sceawere

Vulnerability Detail

CVE-2026-61140Updated Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle WebCenter Sites Critical Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
4h ago
Vendor
Oracle Corporation
Product
Oracle WebCenter Sites
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-07-21T22:18:45.300Z",
  "pubdate": "2026-07-21T22:18:45.300Z",
  "executiveSummary": "This vulnerability affects Oracle WebCenter Sites, a component of Oracle Fusion Middleware, specifically version 14.1.2.0.0. The vulnerability is classified as a critical security flaw that facilitates remote code execution or complete system takeover.\nThe vulnerability is remotely exploitable over a network via the HTTP protocol without the requirement for prior authentication or user interaction. An unauthenticated attacker can achieve full compromise of the affected Oracle WebCenter Sites instance by leveraging the flaw to gain unauthorized administrative control.\nGiven the CVSS 3.1 base score of 9.8, the impact on Confidentiality, Integrity, and Availability is rated as High. The lack of authentication and low attack complexity requirements pose a significant risk, allowing for arbitrary command execution or unauthorized data access. Organizations utilizing the affected version are at extreme risk of total service compromise and must prioritize addressing this exposure.",
  "technicalDetails": "The vulnerability resides within the WebCenter Sites component of Oracle Fusion Middleware version 14.1.2.0.0. The security defect allows an unauthenticated, remote attacker to bypass existing security controls and execute arbitrary operations, ultimately leading to a full system takeover.\nThe attack vector is characterized as network-based, utilizing the HTTP protocol to interface with the vulnerable application. Exploitation does not require user interaction or pre-existing credentials, classifying this as a zero-click vulnerability from the perspective of an external attacker. The low attack complexity rating indicates that the flaw is trivial to weaponize once the target environment is identified.\nThe attack flow involves an attacker crafting a specific HTTP request targeting the vulnerable component within Oracle WebCenter Sites. By sending this malicious payload over the network, the attacker exploits the underlying flaw to bypass authentication mechanisms. Upon successful processing of the request, the application executes the attacker-supplied instructions, granting the attacker a foothold with the privileges of the application server process.\nOnce the initial request is processed, the attacker gains the ability to compromise the confidentiality, integrity, and availability of the system. This allows for the unauthorized retrieval of sensitive configuration files, the modification of stored data within the WebCenter Sites database, or the complete disruption of service availability. Furthermore, successful exploitation often leads to further lateral movement within the network, as the attacker leverages the elevated access provided by the compromised middleware instance to target backend systems or integrated infrastructure.\nThe root cause is associated with improper input validation or insecure handling of HTTP requests within the WebCenter Sites environment. Because the vulnerability results in total system compromise, the impact includes full administrative control over the application, the ability to exfiltrate proprietary content, and the potential to execute operating system commands with the privileges of the application process."
}
CVE-2026-61140: Oracle WebCenter Sites Critical Vulnerability (CRITICAL Severity, CVSS: 9.8) - Sceawere