HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-46799Published Modified CNA oracle

CVE-2026-46799: Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites)

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
9.8
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A critical unauthenticated remote takeover vulnerability exists in Oracle WebCenter Sites (versions 12.2.1.4.0 and 14.1.2.0.0), a component of Oracle Fusion Middleware. The vulnerability is reachable over HTTP from any network location and requires no credentials or user interaction. Successful exploitation gives an attacker full control over the affected WebCenter Sites instance, including complete read, write, and denial-of-service capability. No fix versions have been published by Oracle; HarborGuard is tracking the advisory and will make a patched-image rebuild available the moment an upstream fix is released.

HarborGuard Coverage

Detection

Detection for CVE-2026-46799 is available across every HarborGuard environment: the CVE is ingested from upstream advisory feeds within minutes of publication and matched against all container images in customer registries and CI/CD pipelines, including custom-built images layering Oracle WebCenter Sites. Any image running version 12.2.1.4.0 or 14.1.2.0.0 is flagged automatically.

Available
Triage

Triage is available with a CVSS 3.1 score of 9.8 (Critical), surfaced alongside each customer organization's compliance policy weighting to reflect their specific risk tolerance and regulatory context. Alerts are routed to the appropriate team inbox within each customer org based on configured escalation rules for Critical-severity findings.

Available
Patch

Because no fix version has been published by Oracle, no patched-image rebuild is currently available. HarborGuard re-checks the advisory on every ingest cycle and will make a patched rebuild available automatically the moment Oracle publishes an upstream fix; for customers with auto-remediation enabled, that rebuild will trigger a regression test run and open a PR against affected workloads without manual intervention.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the WebCenter Sites HTTP service over a network; the vulnerability is exposed to any host with network access to the target.

  • AuthenticationNot required

    No credentials of any kind are needed; the attack can be launched by a completely unauthenticated external party.

  • Victim interactionNot required

    Exploitation is entirely server-side and requires no action from any user or administrator of the affected system.

  • Attack complexityDetail

    Attack complexity is Low, meaning the exploit is reliable and requires no special conditions, race timing, or environmental prerequisites.

Blast Radius

  • A successful attacker reads all content, configuration data, stored credentials, and session tokens held by the WebCenter Sites application.
  • The attacker writes or modifies any persisted content, site configuration, or user data managed by the platform.
  • The attacker can crash or permanently disable the WebCenter Sites service, taking it offline for all users.
  • Full system takeover means the attacker can pivot from the compromised instance to other services reachable from within the same container or host network.

How HarborGuard Handles This

Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-46799, the primary capability at this time is continuous detection and advisory monitoring. Any image running Oracle WebCenter Sites 12.2.1.4.0 or 14.1.2.0.0 is flagged as Critical in the HarborGuard pipeline and routed according to each customer org's escalation policy. While awaiting an upstream patch, HarborGuard supports compensating-control guidance such as network-policy isolation to restrict HTTP access to WebCenter Sites to known-good source ranges, egress filtering to limit lateral movement from a compromised instance, and feature-flag or WAF-based gating in front of the affected HTTP endpoint. HarborGuard re-evaluates the Oracle advisory on every ingest cycle; the moment Oracle publishes a fix, a patched-image rebuild at the fixed version becomes available automatically. For customers with auto-remediation enabled, that rebuild is followed immediately by a regression-test run and a PR opened against affected workloads, with a median time from patch publication to merged PR of around 90 minutes for Critical-severity issues.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Oracle WebCenter Sites
    12.2.1.4.0 · 14.1.2.0.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References