CRITICAL 9.8 CVE-2026-61018 Published 18 Aug 2026

Oracle WebCenter Sites Unauthenticated Takeover Vulnerability

Worried this affects one of your servers?

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions affected are 12.2.1.4.0 and 14.1.2.0.0.

This easily exploitable unauthenticated takeover vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks can result in full takeover of the product.

  • Affected versions: 12.2.1.4.0 and 14.1.2.0.0
  • Attack vector: network access via HTTP
  • Prerequisites: none (unauthenticated)
  • CVSS 3.1 Base Score: 9.8 (Confidentiality, Integrity, Availability impacts)

Reference: CVE-2026-61018 on NVD

← Back to Security News