Oracle disclosed a critical, easily exploitable vulnerability in Oracle WebCenter Sites that lets an unauthenticated remote attacker take over the product entirely over HTTP.
What Is It
CVE-2026-61018 is a vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware, in the WebCenter Sites component itself. Per Oracle's advisory data, it is an "easily exploitable" flaw that allows an unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks result in full takeover of the product.
It carries a CVSS 3.1 base score of 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, no user interaction, and high impact to confidentiality, integrity, and availability. The record was published 2026-08-18 and is sourced from Oracle ([email protected]), with NVD status still listed as "Received."
Why It Matters
The combination here is the worst-case set: no credentials, no user interaction, low attack complexity, and network reachability over HTTP. Anything an attacker can reach is a candidate. WebCenter Sites is a web experience management platform, so affected instances are typically internet-facing by design; which collapses the gap between "vulnerable" and "reachable."
The stated outcome is not data disclosure or denial of service alone. It is takeover of Oracle WebCenter Sites, with high confidentiality, integrity, and availability impact across the board.
There is no CISA KEV entry supplied for this CVE, so there is no confirmed evidence of active exploitation in the wild at the time of writing. That is not a reason to defer patching a 9.8 pre-auth takeover.
What's Vulnerable
Oracle Corporation; Oracle WebCenter Sites, supported versions:
- 12.2.1.4.0
- 14.1.2.0.0
No affected CPE entries were listed in the NVD record. No other Fusion Middleware components are named in the supplied data.
Patch Status
Fixes for Oracle products ship through Oracle's Critical Patch Update program, but the source material for this CVE does not identify which Critical Patch Update or Security Alert carries the WebCenter Sites fix. Administrators should consult Oracle's security alerts index directly to locate the advisory covering CVE-2026-61018 and apply the corresponding patches to affected 12.2.1.4.0 and 14.1.2.0.0 deployments, checking both the quarterly CPUs and any out-of-cycle Security Alerts. No specific required-action deadline or KEV due date was provided in the source material.
Sources
- Oracle Security Alerts index; https://www.oracle.com/security-alerts/
- Oracle Critical Patch Update Advisory (July 2026), https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-61018, https://nvd.nist.gov/vuln/detail/CVE-2026-61018