CVE-2026-21962: Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Midd...
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
Security readout for executives and security teams
Plain-English summary
This critical Oracle middleware flaw can let an unauthenticated network attacker read, create, delete, or alter critical data through exposed HTTP services. Because exploitation is listed in CISA’s Known Exploited Vulnerabilities catalog, affected internet-facing systems should be treated as potentially targeted and investigated promptly.
Executive priority
Treat this as an emergency remediation and compromise-assessment item. Active-exploitation status, unauthenticated network reachability, and potential complete data exposure or modification justify immediate ownership, exposure reduction, patch verification, and incident-response review. Business systems relying on these middleware components may require coordinated maintenance.
Technical view
CVE-2026-21962 is an access-control vulnerability (CWE-284) affecting Oracle HTTP Server and WebLogic Server Proxy Plug-ins. It is remotely exploitable over HTTP without credentials or user interaction. CVSS 3.1 is 10.0, with high confidentiality and integrity impact, no stated availability impact, and possible impact beyond the vulnerable component because scope changes.
Likely exposure
Exposure is highest where affected Oracle HTTP Server or WebLogic proxy plug-ins accept HTTP traffic from untrusted networks. Affected versions are 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0; the IIS plug-in is affected only at 12.2.1.4.0. Internal deployments remain exposed to attackers with network reachability.
Exploitation context
CISA KEV status supports active exploitation in the wild. The supplied evidence does not establish exploitation volume, targeted sectors, indicators of compromise, or a reliable public exploit. Public social-media and GitHub references exist, but their technical claims are not substantiated within the provided bundle.
Researcher notes
The vendor assigns CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N. The provided material identifies improper authorization but does not describe the vulnerable request path, root cause, indicators, patch identifiers, or exploitation mechanics. Do not infer availability impact from the 10.0 score; the supplied vector specifies A:N.
Mitigation direction
Follow Oracle’s January 2026 advisory and apply the applicable vendor update for each affected deployment.
Prioritize internet-facing and externally reachable HTTP endpoints for emergency remediation.
Restrict untrusted network access to vulnerable services until vendor remediation is verified.
Assess connected applications and data stores because successful attacks may cross component boundaries.
Validation and detection
Inventory Oracle HTTP Server and WebLogic proxy plug-in installations, including exact versions and web-server type.
Confirm whether affected HTTP endpoints are reachable from internet or other untrusted networks.
Verify the applicable Oracle January 2026 update is installed using authoritative patch records.
Review HTTP, authentication, and data-change telemetry for unexplained unauthenticated activity or integrity changes.
Investigate downstream systems accessible through the affected proxy because the vulnerability has changed scope.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-284: Authorization and privilege behavior lookup
Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
Exploitation: activeAutomatable: yesTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.