CRITICAL 9.1 CVE-2026-61008 Published 18 Aug 2026

Oracle WebCenter Sites Flaw Allows Unauthenticated Data Access and Modification

Worried this affects one of your servers?

A serious access control vulnerability has been disclosed in Oracle WebCenter Sites, part of Oracle Fusion Middleware. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP.

Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data.

  • Affected versions: 12.2.1.4.0 and 14.1.2.0.0
  • CVSS 3.1 Base Score: 9.1 (Confidentiality and Integrity impacts)
  • CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)

Reference: CVE-2026-61008 on NVD

← Back to Security News