Summary
CVE-2026-83035 is a critical, unauthenticated remote takeover vulnerability affecting Oracle WebCenter Sites, part of Oracle Fusion Middleware. The flaw is remotely exploitable over HTTP without any authentication or user interaction, and successful exploitation can result in a complete compromise ("takeover") of the affected Oracle WebCenter Sites instance. Oracle rates this vulnerability as CRITICAL with a CVSS v3.1 base score of 9.8.
Technical details
- Root cause: The published Oracle advisory record describes an "easily exploitable" flaw in Oracle WebCenter Sites that allows an unauthenticated attacker with network access via HTTP to compromise the product; Oracle has not released additional low-level technical detail (e.g., the specific vulnerable component, endpoint, or CWE classification) in the public record.
- Trigger conditions: No authentication or privileges are required, and no user interaction is needed — the attacker only needs network (HTTP) access to a vulnerable WebCenter Sites deployment.
- Attack vector: Network (remote), Attack Complexity: Low, Privileges Required: None, User Interaction: None.
- Impact: High impact to confidentiality, integrity, and availability; Oracle describes the outcome as full takeover of the Oracle WebCenter Sites system.
Affected software
- Oracle WebCenter Sites, version 12.2.1.4.0
- Oracle WebCenter Sites, version 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Patch Update / Security Alert that addresses CVE-2026-83035 for Oracle WebCenter Sites 12.2.1.4.0 and 14.1.2.0.0, as published in Oracle’s security advisory (cspusep2026). Oracle strongly recommends applying vendor-provided patches as soon as possible due to the ease and impact of exploitation.
- If immediate patching is not possible:
- Restrict network access to Oracle WebCenter Sites management and application interfaces to trusted internal networks or VPN only; do not expose the service directly to the public internet.
- Place a web application firewall (WAF) or reverse proxy in front of the application to monitor and restrict anomalous HTTP requests until the patch can be applied.
- Monitor Oracle WebCenter Sites logs for unusual or unauthenticated administrative actions, unexpected process execution, or newly created accounts/content that could indicate exploitation attempts.
- Review Oracle’s advisory for any additional configuration-based workarounds once further technical detail is published.

