Oracle disclosed a critical (CVSS 9.1) vulnerability in Oracle WebCenter Sites that lets an unauthenticated remote attacker read and modify all data the product can access over HTTP.
What Is It
CVE-2026-61008 is a vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware, in the WebCenter Sites component itself. Oracle describes it as an easily exploitable flaw allowing an unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.
Successful attacks can result in unauthorized creation, deletion, or modification of critical data, or all Oracle WebCenter Sites accessible data, as well as unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data.
The CVE was published on 2026-08-18 by Oracle ([email protected]) and currently carries NVD status "Received."
Why It Matters
The CVSS 3.1 base score is 9.1 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. That breaks down to network attack vector, low attack complexity, no privileges required, and no user interaction; the full set of conditions that make a bug trivially reachable from the internet. Exploitability scores 3.9 (the maximum); impact scores 5.2 with High confidentiality and High integrity impact and no availability impact.
WebCenter Sites is a web experience management platform, so instances are frequently internet-facing by design. An attacker needs no credentials and no help from a user.
No CISA KEV entry was supplied for this CVE, so there is no confirmed active exploitation and no KEV-mandated remediation deadline at this time.
What's Vulnerable
Per Oracle, the affected supported versions are:
- Oracle WebCenter Sites 12.2.1.4.0
- Oracle WebCenter Sites 14.1.2.0.0
No CPE entries were listed in the NVD record.
Patch Status
The single reference provided is Oracle's August 2026 Critical Patch Update security alert page. Administrators running the affected versions should consult that advisory and apply the associated fixes. No workaround, mitigation, or required-action deadline is specified in the supplied source material.
Sources
- NVD, CVE-2026-61008 record (source: [email protected])
- Oracle Critical Patch Update Advisory, August 2026; https://www.oracle.com/security-alerts/cspuaug2026.html