SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61018 2026-08-18

Oracle WebCenter Sites Hit With 9.8 Unauthenticated Takeover Flaw (CVE-2026-61018)

"Oracle disclosed a critical, easily exploitable vulnerability in Oracle WebCenter Sites that lets an unauthenticated remote attacker take over the product entirely over HTTP."

Oracle disclosed a critical, easily exploitable vulnerability in Oracle WebCenter Sites that lets an unauthenticated remote attacker take over the product entirely over HTTP.

What Is It

CVE-2026-61018 is a vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware, in the WebCenter Sites component itself. Per Oracle's advisory data, it is an "easily exploitable" flaw that allows an unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks result in full takeover of the product.

It carries a CVSS 3.1 base score of 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, no user interaction, and high impact to confidentiality, integrity, and availability. The record was published 2026-08-18 and is sourced from Oracle ([email protected]), with NVD status still listed as "Received."

Why It Matters

The combination here is the worst-case set: no credentials, no user interaction, low attack complexity, and network reachability over HTTP. Anything an attacker can reach is a candidate. WebCenter Sites is a web experience management platform, so affected instances are typically internet-facing by design; which collapses the gap between "vulnerable" and "reachable."

The stated outcome is not data disclosure or denial of service alone. It is takeover of Oracle WebCenter Sites, with high confidentiality, integrity, and availability impact across the board.

There is no CISA KEV entry supplied for this CVE, so there is no confirmed evidence of active exploitation in the wild at the time of writing. That is not a reason to defer patching a 9.8 pre-auth takeover.

What's Vulnerable

Oracle Corporation; Oracle WebCenter Sites, supported versions:

No affected CPE entries were listed in the NVD record. No other Fusion Middleware components are named in the supplied data.

Patch Status

Fixes for Oracle products ship through Oracle's Critical Patch Update program, but the source material for this CVE does not identify which Critical Patch Update or Security Alert carries the WebCenter Sites fix. Administrators should consult Oracle's security alerts index directly to locate the advisory covering CVE-2026-61018 and apply the corresponding patches to affected 12.2.1.4.0 and 14.1.2.0.0 deployments, checking both the quarterly CPUs and any out-of-cycle Security Alerts. No specific required-action deadline or KEV due date was provided in the source material.

Sources