Summary
CVE-2026-61011 is a high-severity vulnerability affecting Oracle WebCenter Sites, Oracle’s web content management platform within Oracle Fusion Middleware. The flaw allows an unauthenticated, network-based attacker to make unauthorized creation, deletion, or modification of critical application data, and can also cause a partial denial of service. Oracle disclosed the issue in its August 2026 Critical Patch Update, assigning it a CVSS v3.1 base score of 8.2 (High).
Technical details
- Root cause: The vulnerability lies within a component of Oracle WebCenter Sites that fails to properly restrict data-altering operations, permitting unauthorized create/delete/modify actions against critical data.
- Trigger conditions: Exploitation is described by Oracle as "easily exploitable" and requires no authentication or user interaction.
- Attack vector: Network (AV:N) — the attacker only needs HTTP access to the exposed WebCenter Sites instance; no privileges (PR:N) or user interaction (UI:N) are required, and attack complexity is low (AC:L).
- Impact: Successful exploitation results in high integrity impact (unauthorized modification/creation/deletion of critical data) and low availability impact (partial denial of service). Confidentiality is not affected (C:N), and the scope is unchanged (S:U).
Affected software
- Oracle WebCenter Sites version 12.2.1.4.0
- Oracle WebCenter Sites version 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 8.2 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s Critical Patch Update / Security Alert released August 2026 for the affected WebCenter Sites versions (12.2.1.4.0 and 14.1.2.0.0). Organizations should update to the patched releases specified in Oracle’s advisory as soon as possible.
- If immediate patching is not possible: Restrict network access to WebCenter Sites management and content interfaces (e.g., via firewall rules, VPN, or IP allow-listing) so that only trusted internal networks can reach the application over HTTP/HTTPS, reducing exposure to unauthenticated network attackers until the patch can be applied.
- Review WebCenter Sites logs for signs of unauthorized data creation, deletion, or modification, and for indicators of denial-of-service activity, as part of ongoing monitoring while remediation is completed.

