CRITICAL 9 CVE-2026-61029 Published 18 Aug 2026

Oracle WebCenter Sites Unauthenticated Takeover Vulnerability

Worried this affects one of your servers?

A vulnerability has been reported in Oracle WebCenter Sites, part of Oracle Fusion Middleware. It is an unauthenticated takeover vulnerability that can be exploited over HTTP by a remote attacker.

Affected versions are 12.2.1.4.0 and 14.1.2.0.0. The vulnerability is difficult to exploit and requires no authentication or user interaction.

  • Attack vector: network access via HTTP
  • Preconditions: unauthenticated, difficult to exploit
  • Scope change: attacks may significantly impact additional products
  • Impact: successful attacks can result in takeover of Oracle WebCenter Sites
  • CVSS 3.1 Base Score: 9.0 (High confidentiality, integrity, and availability impacts)

Reference: CVE-2026-61029 on NVD

← Back to Security News