A critical, easily exploitable flaw in Oracle WebCenter Sites 14.1.2.0.0 lets unauthenticated attackers take over the product over the network via HTTP, carrying a CVSS 3.1 base score of 9.8.
What Is It
CVE-2026-61140 is a vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Per Oracle's NVD record, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks can result in full takeover of the product. It is rated CVSS 3.1 base score 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Why It Matters
The metrics describe a worst-case profile: network attack vector, low attack complexity, no privileges required, and no user interaction, combined with HIGH impact to confidentiality, integrity, and availability. In practical terms, a remote attacker who can reach the HTTP interface can seize control of the WebCenter Sites instance without credentials or user interaction. There is no CISA KEV entry in the supplied material, so active exploitation is not confirmed at this time, but the low barrier to exploitation makes this a high-priority patch candidate.
What's Vulnerable
According to the NVD record, the affected supported version is Oracle WebCenter Sites 14.1.2.0.0 (vendor: Oracle Corporation). No other versions or CPEs are listed in the supplied data.
Patch Status
This CVE was published by Oracle (source identifier [email protected]) on 2026-07-21 and is tied to Oracle's July 2026 Critical Patch Update. The supplied material does not include a KEV-mandated remediation deadline. Organizations should consult the referenced Oracle Critical Patch Update advisory below for fix availability and apply the associated update. The NVD vulnerability status is currently "Received."
Sources
- Oracle Critical Patch Update Advisory – July 2026; https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-61140, https://nvd.nist.gov/vuln/detail/CVE-2026-61140