Summary
CVE-2026-61045 is a high-severity vulnerability in Oracle WebCenter Sites that allows an unauthenticated, remote attacker with network access via HTTP to compromise the application. Successful exploitation can result in unauthorized access to critical data — up to and including complete access to all data accessible to WebCenter Sites — along with limited unauthorized modification and partial denial of service. Oracle disclosed the issue as part of its August 2026 Critical Security Patch Update, and it carries a CVSS v3.1 base score of 8.6 (High).
Technical details
- Root cause: The CVE record describes the flaw as "easily exploitable," affecting a component of Oracle WebCenter Sites; Oracle has not published low-level technical root-cause detail (e.g., specific class/endpoint) beyond the advisory reference.
- Trigger conditions: No authentication or user interaction is required; the attacker only needs network access to the WebCenter Sites HTTP interface.
- Attack vector: Network (AV:N), Low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: High confidentiality impact (unauthorized access to critical/complete data), low integrity impact (limited unauthorized modification/deletion of accessible data), and low availability impact (partial denial of service). Scope is unchanged (S:U).
Affected software
- Oracle WebCenter Sites 12.2.1.4.0
- Oracle WebCenter Sites 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 8.6 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Mitigation and recommended actions
- Immediate: Apply the fixes provided by Oracle in the August 2026 Critical Security Patch Update (CSPU) for the affected WebCenter Sites releases (12.2.1.4.0 and 14.1.2.0.0). Oracle strongly recommends applying critical patch updates as soon as possible, as these vulnerabilities are remotely exploitable without authentication.
- If immediate patching is not possible: Restrict network access to WebCenter Sites management and application HTTP interfaces to trusted networks only (e.g., via firewall rules or VPN), since the vulnerability requires only network-level HTTP access and no credentials.
- Monitor Oracle’s official advisory for any updated guidance or additional affected components as further details are published.

