Back to Labs
Security Advisory

CVE-2026-21962

About

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

Weakness (CWE):CWE-284

Rainforest analyst review

This flaw is in the Oracle WebLogic Server Proxy Plug-in, the module that fronts WebLogic behind Apache HTTP Server or IIS. An unauthenticated attacker with only HTTP network access can exploit it to gain unauthorized creation, deletion, or modification of, and complete read access to, the data reachable through the proxy. Oracle flags a scope change, meaning the impact extends beyond the plug-in itself into the products it fronts, which is why it carries a maximum 10.0 score despite no direct availability impact.

The proxy plug-in sits at the web tier in front of WebLogic application servers, a component that is by design internet-facing and handles untrusted HTTP, so a pre-auth flaw there is an attractive, low-effort target against enterprise middleware that historically draws heavy scanning and exploitation. Affected versions are 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 (with the IIS plug-in affected only at 12.2.1.4.0). Apply the fixes from the relevant Oracle Critical Patch Update promptly, prioritize any instance exposed to the internet, and restrict access to the web tier while the update is rolled out.

References

Related CVEs

Frequently asked questions

What is CVE-2026-21962?

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0.

How severe is CVE-2026-21962?

CVE-2026-21962 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.

How is CVE-2026-21962 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability None.

Which products are affected by CVE-2026-21962?

Public advisories list the following as affected: http server, weblogic server proxy plug-in. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2026-21962?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email