CRITICAL 9.9 CVE-2026-61021 Published 18 Aug 2026

Oracle WebCenter Sites Remote Takeover Vulnerability

Worried this affects one of your servers?

A vulnerability has been reported in Oracle WebCenter Sites, a component of Oracle Fusion Middleware. The flaw is a remote takeover vulnerability that affects supported versions 12.2.1.4.0 and 14.1.2.0.0.

The issue is easily exploitable by a low-privileged attacker with network access via HTTP. Successful attacks can result in takeover of Oracle WebCenter Sites, and the impact may extend to additional products due to a scope change.

  • Affected versions: 12.2.1.4.0 and 14.1.2.0.0
  • Attack vector: network access via HTTP
  • Required privileges: low
  • Impact: takeover, with high confidentiality, integrity, and availability impacts
  • CVSS 3.1 Base Score: 9.9

Reference: CVE-2026-61021 on NVD

← Back to Security News