CVE-2026-46797: Critical severity Oracle Oracle WebCenter Sites vulnerability
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to Oracle WebCenter Sites HTTP endpoints to trusted IPs using firewall/ACLs; deny HTTP access from untrusted networks (block internet access to the service)
- Compensating control
Deploy a web application firewall (WAF) or intrusion detection/prevention system in front of Oracle WebCenter Sites to detect and block exploit attempts over HTTP
- Operational
If Oracle WebCenter Sites instances are internet-facing, consider temporarily disabling or isolating their HTTP exposure (take offline or place on an isolated network segment) until an official vendor fix is available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46797?
CVE-2026-46797 has a critical severity rating of 9.8.
How do I fix CVE-2026-46797?
To fix CVE-2026-46797, ensure that you patch or upgrade to the latest supported version of Oracle WebCenter Sites.
What is the impact of CVE-2026-46797?
CVE-2026-46797 allows an unauthenticated attacker to compromise the Oracle WebCenter Sites product via HTTP.
Which versions are affected by CVE-2026-46797?
CVE-2026-46797 affects Oracle WebCenter Sites versions 12.2.1.4.0 and 14.1.2.0.0.
How can I protect against CVE-2026-46797?
To protect against CVE-2026-46797, apply recommended patches and restrict network access to the affected Oracle WebCenter Sites components.