Skip to main content
QUIETLYTIC
Vulnerability

Oracle HTTP Server Access Control Flaw (CVE-2026-21962)

CVE-2026-21962 is a CVSS 10.0 access control flaw in Oracle HTTP Server and the WebLogic Proxy Plug-in, KEV-listed Aug. 24, 2026, EPSS at the 98th percentile.

CVE-2026-21962
Threat Level
CRITICAL
CVSS
10.0
Status
Active Exploitation
Confidence
High
Affected Products
Oracle HTTP Server, Oracle WebLogic Server Proxy Plug-in

CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog on August 24, 2026 — seven months after NVD published the record on January 20, 2026, as part of Oracle’s January 2026 Critical Patch Update. NVD scores it CVSS 3.1 base 10.0, and FIRST’s EPSS model places it at the 98.6th percentile of all scored CVEs.

An access-control failure at the proxy layer

The flaw sits in Oracle Fusion Middleware, specifically the WebLogic Server Proxy Plug-in for Apache HTTP Server and the equivalent plug-in for IIS. NVD, CISA KEV and VulnCheck KEV all classify it as CWE-284, improper access control.

Per NVD’s record, the vulnerability is easily exploitable by an unauthenticated attacker with network access over HTTP, and successful attacks can result in unauthorised creation, deletion or modification of critical data, plus unauthorised access to all data reachable through Oracle HTTP Server and the proxy plug-in. NVD’s record also notes that while the vulnerability lives in the plug-in, attacks may significantly affect additional products — the scope change reflected in the CVSS vector.

Affected versions per NVD are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0, with one qualification the record states explicitly: for the WebLogic Server Proxy Plug-in for IIS, only 12.2.1.4.0 is affected.

The unusual shape of a 10.0

NVD’s vector is AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N. Read the last component carefully — availability impact is None. This is a CVSS 10.0 that does not take the service down.

What lifts it to a perfect score instead is the combination of full network reach with no privileges or user interaction required (AV:N/AC:L/PR:N/UI:N) and a scope change (S:C). A proxy plug-in is, by construction, a component that speaks on behalf of something else; when its access controls fail, the consequence lands on the application server behind it rather than staying in the plug-in. That is precisely what a scope change encodes, and it is why the confidentiality and integrity impacts alone are enough here.

The practical reading: this is a data-exposure and data-tampering problem against whatever the proxy fronts, not a denial-of-service problem. Teams triaging by “will it take production down” will mis-rank it.

What the evidence supports

Claim Value Sources agreeing Confidence
Exploitation status KEV-listed, known exploited CISA KEV, VulnCheck KEV High
KEV date added 2026-08-24 CISA KEV, VulnCheck KEV High
Weakness class CWE-284 NVD, CISA KEV, VulnCheck KEV High
Vendor and product Oracle, HTTP Server / WebLogic Proxy Plug-in CISA KEV, VulnCheck KEV High
EPSS score 0.4202 (98.6th percentile) FIRST EPSS only Medium
CVSS score and vector 10.0, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N NVD only Medium
Affected versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 NVD only Medium

EPSS at 0.4202 means the model estimates a roughly 42% probability of exploitation activity being observed in the next 30 days. That is a high absolute figure — the vast majority of CVEs score in the low single-digit percentages, which is what puts this one in the 98.6th percentile. It is also, in this case, partly redundant: CISA has already confirmed exploitation, so EPSS functions as corroboration of a known fact rather than a forecast of an unknown one.

Why this matters

Three things separate this from an ordinary critical CVE.

First, the seven-month exposure window. A patch shipped with Oracle’s January 2026 Critical Patch Update. Anything still unpatched when CISA listed it in August had been remediable for more than half a year, which makes this a patch-management question more than a zero-day response.

Second, the position in the stack. The WebLogic Proxy Plug-in is deployed in front of application servers, which means it typically sits at an internet-facing or DMZ boundary in exactly the deployments large enough to have one. Instances tend to be long-lived, infrequently touched, and owned by a middleware team rather than the group that patches application code.

Third, the combination of KEV listing and a 98.6th-percentile EPSS score. Either signal alone justifies prioritisation; together they make this one of the strongest patch-priority cases in the current KEV window — comparable to Cisco’s CVE-2026-20079 Secure Firewall Management Center authentication bypass, also a CVSS 10.0 KEV entry against a privileged management component, and to Citrix NetScaler’s CVE-2026-19490, another unauthenticated access-control bypass on a component that sits at the network edge.

Intelligence gaps

  • No attribution data. Our pipeline carries no threat-actor, campaign or telemetry source. Third-party outlets have published claims linking exploitation of this CVE to specific actors; we have no evidence supporting or refuting them and therefore make no such claim.
  • No structured fixed-version data. The affected versions above come from NVD’s prose. Oracle’s January 2026 Critical Patch Update advisory is the authoritative reference NVD points to for patch levels.
  • No per-field source URLs. Our provenance table records the contributing source for every field but holds no per-field link, so attribution is by source name rather than a constructed URL.
  • CVSS and version data are single-sourced. Both trace to NVD alone in our ingested data, which is why they carry medium confidence even though the exploitation claim does not.

Frequently Asked Questions

What is CVE-2026-21962? An improper access control vulnerability (CWE-284) in the Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS, exploitable by an unauthenticated attacker over HTTP. NVD scores it CVSS 3.1 base 10.0.

Is CVE-2026-21962 actively exploited? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on August 24, 2026, and VulnCheck’s KEV data records the same status and date.

Which versions are affected? Per NVD, versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. For the IIS variant of the proxy plug-in, NVD states only 12.2.1.4.0 is affected.

Why does a flaw with no availability impact score 10.0? Because the CVSS vector combines unauthenticated network reach with a scope change. High confidentiality and integrity impact that crosses into another component is sufficient for a maximum score; availability impact is not required.

Where is the fix? Oracle addressed it in the January 2026 Critical Patch Update. CISA’s KEV entry directs organisations to vendor instructions and BOD 26-04 risk-based patching guidance rather than setting its own fixed deadline.


Data sourced from the National Vulnerability Database (NVD), CISA’s Known Exploited Vulnerabilities (KEV) catalog, FIRST’s EPSS model, and corroborating KEV metadata from VulnCheck, aggregated September 17, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog
03 FIRST EPSS

Related intelligence


Analyst tools