CVE-2026-61038 is a high-severity vulnerability in Oracle WebCenter Sites, a component of Oracle Fusion Middleware, that allows an unauthenticated, remote attacker to gain unauthorized access to sensitive data over HTTP and to make limited unauthorized modifications. Oracle rates the flaw as "easily exploitable," and it carries a CVSS v3.1 base score of 8.2. The CVE was published on August 18, 2026, as part of Oracle's Critical Patch Update.
