← Vulnerability feed

Vulnerability record · CVE-2026-21962 · published 20 January 2026

CVE-2026-21962: Oracle HTTP Server and WebLogic Proxy Plug-in improper access control

Oracle · Http Server

Oracle HTTP Server and the WebLogic Server Proxy Plug-in (for Apache HTTP Server and IIS) contain an improper access control flaw (CWE-284) in supported versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0; the IIS plug-in is affected only at 12.2.1.4.0. It is remotely reachable over HTTP without authentication and carries a CVSS 3.1 base score of 10.0 with scope change, so it warrants immediate attention.

10.0 CVSS 3.1 Critical CISA KEV since 24 Aug 2026 EPSS 71% · top 0.6% CWE-284 · Improper access control
10.0CVSS 3.1 base score
71%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
5References
25 Aug 2026Last modified by NVD

Description

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 10.0, unauthenticated network exploitation, scope change and confirmed CISA KEV listing with a near-term remediation deadline make this an urgent patch.

What it is

Oracle HTTP Server and the WebLogic Server Proxy Plug-in (for Apache HTTP Server and IIS) contain an improper access control flaw (CWE-284) in supported versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0; the IIS plug-in is affected only at 12.2.1.4.0. It is remotely reachable over HTTP without authentication and carries a CVSS 3.1 base score of 10.0 with scope change, so it warrants immediate attention.

Impact

An unauthenticated attacker can create, delete or modify critical data and gain full read access to data reachable through the affected server and plug-in, with the impact extending to additional products due to scope change. Availability is not listed as impacted in the vector.

Attack surface

Reached over the network via HTTP (AV:N) with no privileges and no user interaction required (PR:N/UI:N), so any internet- or network-exposed Oracle HTTP Server or WebLogic Proxy Plug-in deployment is a candidate target.

Exploitation

CVE-2026-21962 is listed in CISA KEV with a 2026-08-27 remediation due date, and EPSS gives a 0.4202 probability (98.6th percentile), indicating observed exploitation activity. No ransomware campaign use is documented in the record.

What to do

  • Apply the Oracle January 2026 Critical Patch Update fixes for Oracle HTTP Server and the WebLogic Server Proxy Plug-in per the vendor advisory.
  • If patching cannot be completed by the CISA due date, apply the mitigations in Oracle's guidance or discontinue use of the affected component, consistent with BOD 26-04.
  • Restrict network access to the affected HTTP Server and proxy plug-in endpoints to trusted sources; do not leave them internet-exposed where avoidable.
  • Confirm which deployments run the affected versions, noting the IIS plug-in is affected only at 12.2.1.4.0.
  • Track remediation against the CISA KEV due date and escalate any remaining exposed instances.

Detection

  • Review HTTP access logs on Oracle HTTP Server and proxy plug-in hosts for anomalous requests, unexpected URI patterns or access to resources outside normal application paths.
  • Monitor for unauthorized creation, modification or deletion of files and configuration data on affected hosts and downstream systems.
  • Alert on unexpected outbound or lateral connections originating from the affected servers, given the scope-change impact.
  • Audit authentication and access-control decisions on the plug-in for requests that should have been denied but succeeded.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog on 24 August 2026 as "Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 27 August 2026.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-21962 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2021-40438Apache HTTP Server mod_proxy SSRF via crafted URI pathA crafted request URI path can make mod_proxy forward the request to an origin server chosen by the remote user, an SSRF flaw in Apache HTTP Server 2…KEVEPSS 100%analysed7.8CVE-2021-4034polkit pkexec argument handling flaw allows local root escalationpkexec, the setuid polkit utility for running commands as privileged users, mishandles the calling parameter count and ends up treating environment v…KEVEPSS 94%analysed7.8CVE-2019-0211Apache HTTP Server scoreboard use-after-free local privilege escalationApache HTTP Server 2.4.17 through 2.4.38 with MPM event, worker or prefork contains a use-after-free in scoreboard handling. Code running in a less-p…KEVEPSS 65%analysed10.0CVE-2026-60365Oracle http server missing authentication for critical function vulnerabilityVulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Par…EPSS 0.43%10.0CVE-2010-0425Apache mod_isapi on Windows remote code execution via orphaned callbacksmod_isapi in Apache HTTP Server on Windows does not ensure request processing is complete before calling isapi_unload for an ISAPI .dll module, leavi…EPSS 94%analysed10.0CVE-2006-5347Oracle http server vulnerabilityUnspecified vulnerability in Oracle HTTP Server 9.2.0.7 and Oracle Collaboration Suite 9.0.4.2 has unknown impact and remote attack vectors related t…EPSS 2.9%10.0CVE-2006-5348Oracle collaboration suite vulnerabilityUnspecified vulnerability in Oracle HTTP Server 9.2.0.7, Oracle Collaboration Suite 9.0.4.2, and Oracle E-Business Suite and Applications 11.5.10CU2 …EPSS 2.9%10.0CVE-2006-5349Oracle http server vulnerabilityUnspecified vulnerability in Oracle HTTP Server 9.2.0.7, when running on HP Tru64 UNIX, has unknown impact and remote attack vectors related to HTTPS…EPSS 2.9%

Source: NIST National Vulnerability Database (record CVE-2026-21962), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.