Vulnerability record · CVE-2026-21962 · published 20 January 2026
CVE-2026-21962: Oracle HTTP Server and WebLogic Proxy Plug-in improper access control
Oracle · Http Server
Oracle HTTP Server and the WebLogic Server Proxy Plug-in (for Apache HTTP Server and IIS) contain an improper access control flaw (CWE-284) in supported versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0; the IIS plug-in is affected only at 12.2.1.4.0. It is remotely reachable over HTTP without authentication and carries a CVSS 3.1 base score of 10.0 with scope change, so it warrants immediate attention.
Description
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Automated analysis
critical priorityCVSS 10.0, unauthenticated network exploitation, scope change and confirmed CISA KEV listing with a near-term remediation deadline make this an urgent patch.
What it is
Oracle HTTP Server and the WebLogic Server Proxy Plug-in (for Apache HTTP Server and IIS) contain an improper access control flaw (CWE-284) in supported versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0; the IIS plug-in is affected only at 12.2.1.4.0. It is remotely reachable over HTTP without authentication and carries a CVSS 3.1 base score of 10.0 with scope change, so it warrants immediate attention.
Impact
An unauthenticated attacker can create, delete or modify critical data and gain full read access to data reachable through the affected server and plug-in, with the impact extending to additional products due to scope change. Availability is not listed as impacted in the vector.
Attack surface
Reached over the network via HTTP (AV:N) with no privileges and no user interaction required (PR:N/UI:N), so any internet- or network-exposed Oracle HTTP Server or WebLogic Proxy Plug-in deployment is a candidate target.
Exploitation
CVE-2026-21962 is listed in CISA KEV with a 2026-08-27 remediation due date, and EPSS gives a 0.4202 probability (98.6th percentile), indicating observed exploitation activity. No ransomware campaign use is documented in the record.
What to do
- Apply the Oracle January 2026 Critical Patch Update fixes for Oracle HTTP Server and the WebLogic Server Proxy Plug-in per the vendor advisory.
- If patching cannot be completed by the CISA due date, apply the mitigations in Oracle's guidance or discontinue use of the affected component, consistent with BOD 26-04.
- Restrict network access to the affected HTTP Server and proxy plug-in endpoints to trusted sources; do not leave them internet-exposed where avoidable.
- Confirm which deployments run the affected versions, noting the IIS plug-in is affected only at 12.2.1.4.0.
- Track remediation against the CISA KEV due date and escalate any remaining exposed instances.
Detection
- Review HTTP access logs on Oracle HTTP Server and proxy plug-in hosts for anomalous requests, unexpected URI patterns or access to resources outside normal application paths.
- Monitor for unauthorized creation, modification or deletion of files and configuration data on affected hosts and downstream systems.
- Alert on unexpected outbound or lateral connections originating from the affected servers, given the scope-change impact.
- Audit authentication and access-control decisions on the plug-in for requests that should have been denied but succeeded.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog on 24 August 2026 as "Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 27 August 2026.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.oracle.com/security-alerts/cpujan2026.html | PatchVendor Advisory |
| https://github.com/Ashwesker/Ashwesker-CVE-2026-21962/issues/1 | Broken LinkNot Applicable |
| https://web.archive.org/web/20260129165916/https://github.com/Ashwesker/Ashwesker-CVE-2026-21962/issues/1 | Issue Tracking |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-21962 | US Government Resource |
| https://x.com/0xacb/status/2015473216844620280 | Not Applicable |
Track CVE-2026-21962 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-21962), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.