SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61034 2026-08-18

Oracle WebCenter Sites Hit by Critical CVE-2026-61034 — CVSS 9.1 Flaw Enables Full Product Takeover

"Oracle's August 2026 Critical Patch Update fixes CVE-2026-61034, a CVSS 9.1 flaw in Oracle WebCenter Sites that lets a high-privileged network attacker take over the product and reach beyond it into adjacent systems."

Oracle's August 2026 Critical Patch Update fixes CVE-2026-61034, a CVSS 9.1 flaw in Oracle WebCenter Sites that lets a high-privileged network attacker take over the product and reach beyond it into adjacent systems.

What Is It

CVE-2026-61034 is a vulnerability in the WebCenter Sites component of Oracle Fusion Middleware's Oracle WebCenter Sites product. Oracle describes it as easily exploitable: an attacker with high privileges and network access over HTTP can compromise the product outright, with no user interaction required.

The CVSS 3.1 vector is AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, scoring 9.1 (Critical) with a 2.3 exploitability subscore and a 6.0 impact subscore. Confidentiality, integrity, and availability impacts are all rated High.

Why It Matters

The defining detail is the scope change (S:C). While the vulnerability itself resides in Oracle WebCenter Sites, Oracle states that successful attacks "may significantly impact additional products"; meaning compromise does not stay contained within the vulnerable component. Successful exploitation results in takeover of Oracle WebCenter Sites.

That scope change is what pushes an otherwise privilege-gated bug into Critical territory. The high-privileges requirement narrows the pool of potential attackers to those who already hold elevated access, but it does not blunt the outcome: full compromise of the product, plus blast radius into other systems in the Fusion Middleware footprint. Low attack complexity and no user-interaction requirement mean nothing stands between an attacker holding those credentials and the takeover.

What's Vulnerable

Per Oracle Corporation, the affected supported versions of Oracle WebCenter Sites are:

The record was published to NVD on 2026-08-18 with a status of "Received," sourced from Oracle's security alert address. No CPE match data is present in the record yet.

Patch Status

Fixes are delivered via Oracle's Critical Patch Update for August 2026. Administrators running either affected version should apply the CPU advisory patches referenced below.

There is no CISA KEV entry for CVE-2026-61034 in the supplied data; active exploitation is not confirmed, and no federal remediation deadline applies at this time.

Sources