CVE-2026-46799: Critical severity Oracle WebCenter Sites vulnerability
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable or restrict HTTP access to Oracle WebCenter Sites so that it is not directly accessible from untrusted/public networks. Allow access only from trusted IP ranges or internal network segments; if public access is required, place the service behind an authenticated reverse proxy or gateway.
Oracle WebCenter Sites HTTP access = restricted to trusted IPs or disabled for public access - Compensating control
At the network perimeter and internal firewalls, restrict access to the Oracle WebCenter Sites HTTP endpoints to trusted administration/application hosts only (use ACLs or firewall rules to block all other sources).
- Compensating control
Deploy a web application firewall (WAF) or intrusion prevention system in front of Oracle WebCenter Sites to detect and block exploitation attempts against HTTP endpoints.
- Operational
Treat affected instances as potentially compromised (vulnerability may allow takeover): monitor logs and network traffic for signs of compromise, perform forensic analysis if suspicious activity is found, and restore from known-good backups if compromise is confirmed.
- Operational
Rotate credentials, API keys, and secrets used by Oracle WebCenter Sites and related systems if there is any possibility they were exposed; isolate affected hosts from network until mitigations are applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46799?
The severity of CVE-2026-46799 is rated critical with a CVSS score of 9.8.
How do I fix CVE-2026-46799?
To fix CVE-2026-46799, you should update Oracle WebCenter Sites to the latest patched version provided by Oracle.
What versions are affected by CVE-2026-46799?
The affected versions of Oracle WebCenter Sites for CVE-2026-46799 are 12.2.1.4.0 and 14.1.2.0.0.
Can CVE-2026-46799 be exploited remotely?
Yes, CVE-2026-46799 can be exploited remotely by an unauthenticated attacker with network access via HTTP.
What components of Oracle Fusion Middleware are impacted by CVE-2026-46799?
CVE-2026-46799 impacts the WebCenter Sites component of Oracle Fusion Middleware.