CVE-2026-46798
CRITICAL
10.0
CVSS 3.1
Metadata
Severity & Metrics
10.0
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Oracle Corporation | Oracle WebCenter Sites | — | 12.2.1.4.0, 14.1.2.0.0 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. |
| CWE-306 | adp | CWE-306 Missing Authentication for Critical Function |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 10.0 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
References (1)
- Oracle Advisory https://www.oracle.com/security-alerts/cspujun2026.html