Summary
CVE-2026-83036 is a critical vulnerability in Oracle WebCenter Sites, a component of Oracle Fusion Middleware, that allows an unauthenticated attacker with network access via HTTP to fully compromise the affected system. Oracle describes the flaw as "easily exploitable," and successful exploitation results in complete takeover of Oracle WebCenter Sites, impacting confidentiality, integrity, and availability. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and was disclosed by Oracle on September 15, 2026.
Technical details
- Root cause: Oracle’s advisory record does not disclose the specific underlying flaw (e.g., no CWE classification is published in the CVE record); Oracle characterizes it only as an easily exploitable defect reachable over HTTP.
- Trigger conditions: No authentication or user interaction is required to trigger the vulnerability; it is exploitable by any attacker with network access to the exposed WebCenter Sites HTTP interface.
- Attack vector: Network (AV:N) — remote, over HTTP, with low attack complexity (AC:L) and no privileges required (PR:N).
- Impact: Full compromise ("takeover") of the affected Oracle WebCenter Sites installation, with high impact to confidentiality, integrity, and availability (C:H/I:H/A:H). Given the network-reachable, unauthenticated nature of the flaw, internet-exposed WebCenter Sites instances are at high risk of complete system compromise.
Affected software
- Oracle WebCenter Sites 12.2.1.4.0
- Oracle WebCenter Sites 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s September 2026 Critical Patch Update (Security Alert) for Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0. Organizations should consult Oracle’s official advisory to identify and install the specific patch corresponding to their deployed version.
- If patching cannot be applied immediately: Restrict network access to Oracle WebCenter Sites HTTP interfaces (e.g., via firewall rules, VPN, or network segmentation) so they are not directly reachable from the internet, and monitor for anomalous or unauthenticated access attempts until the patch can be applied. No official workaround beyond patching has been published by Oracle.

