SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61021 2026-08-18

Oracle WebCenter Sites Hit With 9.9-Severity Takeover Flaw (CVE-2026-61021)

"CVE-2026-61021 is a critical, easily exploitable vulnerability in Oracle WebCenter Sites that lets a low-privileged network attacker fully take over the product, with Oracle warning that impact may extend beyond it into…"

CVE-2026-61021 is a critical, easily exploitable vulnerability in Oracle WebCenter Sites that lets a low-privileged network attacker fully take over the product, with Oracle warning that impact may extend beyond it into adjacent systems.

What Is It

CVE-2026-61021 is a vulnerability in the WebCenter Sites component of Oracle WebCenter Sites, part of the Oracle Fusion Middleware stack. Oracle describes it as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks result in complete takeover of the product.

The CVSS 3.1 base score is 9.9 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, network attack vector, low attack complexity, low privileges required, no user interaction, and a changed scope with high confidentiality, integrity, and availability impact.

Why It Matters

The scope change is what pushes this from "bad" to "worst tier." Oracle explicitly notes that while the vulnerability lives in WebCenter Sites, attacks may significantly impact additional products. Oracle does not state that adjacent systems are always reachable, but the changed scope means defenders should not assume a compromise is contained at the CMS boundary.

The only barrier is a low-privileged account. Neither Oracle nor NVD specifies which roles or privilege levels are sufficient, so the practical bar cannot be pinned down from the available data. What the vector does establish is that full administrative access is not required; so in any deployment where lower-tier accounts (for example content or service accounts) are provisioned broadly, the population of accounts capable of reaching the flaw would be correspondingly larger than "authenticated" suggests. Defenders should audit their own role assignments rather than assume a particular account tier is or is not in scope. No user interaction is required, and Oracle characterizes exploitation as easy.

There is no CISA KEV entry for CVE-2026-61021 in the supplied data, so active exploitation is not currently confirmed.

What's Vulnerable

Per Oracle, the affected supported versions are:

Patch Status

The fix is delivered through an Oracle Critical Patch Update. One caveat on sourcing: the advisory identifier carried in the supplied data (cspuaug2026, an August 2026 CPU) does not correspond to Oracle's release cadence, Oracle ships Critical Patch Updates quarterly, in January, April, July, and October, and the corresponding advisory path could not be verified. Administrators should locate the fix through Oracle's official Critical Patch Update advisory index and the My Oracle Support patch listings for their release, rather than relying on that identifier.

Organizations running either affected version should apply the relevant CPU patches per Oracle's advisory. No specific remediation deadline is present in the supplied data, and no workaround is documented in the source material.

Sources