SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61008 2026-08-18

CVE-2026-61008: Unauthenticated Critical Flaw in Oracle WebCenter Sites

"Oracle disclosed a critical (CVSS 9.1) vulnerability in Oracle WebCenter Sites that lets an unauthenticated remote attacker read and modify all data the product can access over HTTP."

Oracle disclosed a critical (CVSS 9.1) vulnerability in Oracle WebCenter Sites that lets an unauthenticated remote attacker read and modify all data the product can access over HTTP.

What Is It

CVE-2026-61008 is a vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware, in the WebCenter Sites component itself. Oracle describes it as an easily exploitable flaw allowing an unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.

Successful attacks can result in unauthorized creation, deletion, or modification of critical data, or all Oracle WebCenter Sites accessible data, as well as unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data.

The CVE was published on 2026-08-18 by Oracle ([email protected]) and currently carries NVD status "Received."

Why It Matters

The CVSS 3.1 base score is 9.1 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. That breaks down to network attack vector, low attack complexity, no privileges required, and no user interaction; the full set of conditions that make a bug trivially reachable from the internet. Exploitability scores 3.9 (the maximum); impact scores 5.2 with High confidentiality and High integrity impact and no availability impact.

WebCenter Sites is a web experience management platform, so instances are frequently internet-facing by design. An attacker needs no credentials and no help from a user.

No CISA KEV entry was supplied for this CVE, so there is no confirmed active exploitation and no KEV-mandated remediation deadline at this time.

What's Vulnerable

Per Oracle, the affected supported versions are:

No CPE entries were listed in the NVD record.

Patch Status

The single reference provided is Oracle's August 2026 Critical Patch Update security alert page. Administrators running the affected versions should consult that advisory and apply the associated fixes. No workaround, mitigation, or required-action deadline is specified in the supplied source material.

Sources