Summary
CVE-2026-61016 is a high-severity vulnerability in Oracle WebCenter Sites (a component of Oracle Fusion Middleware) that allows an unauthenticated, network-based attacker to compromise the application over HTTP. The flaw enables unauthorized creation, deletion, or modification of critical data, and can also trigger a partial denial-of-service condition. It was disclosed by Oracle on August 18, 2026, with a CVSS v3.1 base score of 8.2 (High).
Technical details
- Root cause: A flaw within Oracle WebCenter Sites permits unauthorized write access to critical application data; Oracle’s advisory record does not disclose the specific vulnerable component, endpoint, or code path.
- Trigger conditions: The vulnerability is remotely exploitable over HTTP without requiring any authentication or user interaction, and Oracle rates attack complexity as Low.
- Attack vector: Network (AV:N) — an attacker only needs network access to the exposed WebCenter Sites HTTP interface to attempt exploitation.
- Impact: Successful exploitation grants unauthorized creation, deletion, or modification ("high integrity impact") of critical data within WebCenter Sites, along with a low-severity availability impact (partial denial of service). Confidentiality is not affected (C:N).
Affected software
- Oracle WebCenter Sites 12.2.1.4.0
- Oracle WebCenter Sites 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 8.2 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Mitigation and recommended actions
- Immediate: Apply the fix provided by Oracle for CVE-2026-61016 as documented in the August 2026 Oracle Critical Security Patch Update advisory. Oracle strongly recommends that customers apply the security patches as soon as possible.
- If no patch can be applied immediately: Restrict network exposure of Oracle WebCenter Sites administrative and content-management interfaces to trusted internal networks or VPN-only access, and monitor for anomalous content creation, deletion, or modification activity until the patch can be deployed. Oracle has not published a specific interim workaround beyond applying the update.

