HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-46796Published Modified CNA oracle

CVE-2026-46796: Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
8.0
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An unspecified high-severity vulnerability affects Oracle WebCenter Sites (versions 12.2.1.4.0 and 14.1.2.0.0), reachable over HTTP from the network by any low-privileged authenticated user. Exploitation requires a separate user to interact with attacker-controlled content, making this a social-engineering-assisted attack. Successful exploitation results in full takeover of the Oracle WebCenter Sites instance, impacting confidentiality, integrity, and availability. No fix version has been published yet; HarborGuard is tracking the advisory for patch availability.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream Oracle and NVD feeds within minutes of publication and matched against customer images, including custom-built images that bundle Oracle WebCenter Sites. Any image running an affected version (12.2.1.4.0 or 14.1.2.0.0) is flagged automatically in both registry scans and CI/CD pipeline checks.

Available
Triage

HarborGuard is capable of scoring this finding at CVSS 8.0 (High) and weighting it against each customer environment's compliance policy to prioritize routing. Findings are surfaced to the appropriate team inbox within each customer org based on image ownership and severity thresholds configured in policy.

Available
Patch

No upstream fix version has been published for this CVE. HarborGuard re-checks the Oracle advisory each ingest cycle and will make a patched-image rebuild available automatically the moment Oracle publishes a fix. For customers with auto-remediation enabled, the rebuild, regression-test run, and PR against affected workloads will be triggered without manual intervention once a fix version exists.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the Oracle WebCenter Sites service over the network via HTTP; there is no local or physical access requirement.

  • AuthenticationRequired

    A low-privilege account is sufficient; any authenticated user can initiate the attack without needing administrator rights.

  • Victim interactionRequired

    A separate, non-attacker user must interact with something (such as a crafted link or page) as part of the attack, introducing a social-engineering dependency.

  • Attack complexityDetail

    Attack complexity is Low, meaning the exploit is straightforward and reliable with no special race conditions or environmental prerequisites required.

Blast Radius

  • Reads all data accessible to the WebCenter Sites application, including stored content, user records, and credentials.
  • Modifies or destroys persisted site content, configurations, and database records managed by WebCenter Sites.
  • Crashes or degrades the WebCenter Sites service, making it unavailable to legitimate users.
  • Full application takeover gives the attacker a foothold to pivot further into connected Fusion Middleware components or backend systems.

How HarborGuard Handles This

Available on HarborGuard: because no upstream fix exists for CVE-2026-46796, the platform monitors the Oracle advisory on every ingest cycle and will surface a patched-image rebuild the moment Oracle publishes a remediated version. In the interim, customers can use HarborGuard network-policy controls to restrict inbound HTTP access to WebCenter Sites to only trusted source IP ranges, reducing exposure to the network-reachable attack vector. Egress filtering can limit the blast radius if the service is compromised. Customers should also review which accounts hold even low-privilege access to WebCenter Sites and tighten authentication policies where possible. When Oracle ships a fix, environments with auto-remediation enabled will receive a rebuilt image, a regression-test run, and a PR opened against affected workloads automatically; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for those environments.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Oracle WebCenter Sites
    12.2.1.4.0 · 14.1.2.0.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
References