Summary
CVE-2026-61038 is a high-severity vulnerability in Oracle WebCenter Sites, a component of Oracle Fusion Middleware, that allows an unauthenticated, remote attacker to gain unauthorized access to sensitive data over HTTP and to make limited unauthorized modifications. Oracle rates the flaw as "easily exploitable," and it carries a CVSS v3.1 base score of 8.2. The CVE was published on August 18, 2026, as part of Oracle’s Critical Patch Update.
Technical details
- Root cause: A weakness in Oracle WebCenter Sites permits access to protected data and functionality without proper authentication or authorization checks; Oracle has not disclosed granular technical/root-cause detail (e.g., specific module, endpoint, or CWE classification) beyond the standard advisory language.
- Trigger conditions: The vulnerability is remotely exploitable over HTTP and requires no authentication credentials and no user interaction, making it reachable by any attacker with network access to the affected WebCenter Sites instance.
- Attack vector: Network (AV:N), with low attack complexity (AC:L) and no privileges required (PR:N), meaning no valid account or prior access is needed to attempt exploitation.
- Impact: Successful exploitation can result in unauthorized access to critical data or complete access to all data accessible to Oracle WebCenter Sites, plus unauthorized update, insert, or delete access to some of that data. There is no reported impact to availability.
Affected software
- Oracle WebCenter Sites version 12.2.1.4.0
- Oracle WebCenter Sites version 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 8.2 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N - Confidentiality: High | Integrity: Low | Availability: None
Mitigation and recommended actions
- Immediate: Apply the official Oracle Critical Patch Update patches for Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0 as released in Oracle’s August 2026 Critical Patch Update advisory. Oracle strongly recommends applying these fixes as soon as possible.
- If patching cannot be completed immediately:
- Restrict network access to Oracle WebCenter Sites management and content-serving interfaces to trusted internal networks or VPNs only, minimizing internet exposure.
- Place WebCenter Sites deployments behind a web application firewall (WAF) or reverse proxy that can monitor and restrict anomalous unauthenticated HTTP requests.
- Review access and application logs for unusual or unauthenticated requests to WebCenter Sites endpoints as an interim detection measure until patches are applied.
- Since the vulnerability requires no authentication, do not rely on account-level controls (e.g., password resets) as a substitute for patching — network-level restriction and prompt patching are the primary effective mitigations.

