Knox CVE Database
/
CVE-2026-21962
Critical
10.0

CVE-2026-21962: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.

Added to the CISA KEV catalog:
August 24, 2026

Overview

Oracle's WebLogic Server Proxy Plug-in, which fronts WebLogic backends from Apache HTTP Server or IIS, fails to enforce authorization on incoming HTTP requests. An unauthenticated attacker with network access can reach protected resources and read, create, delete or modify the data the proxy can reach, with no credentials and no user interaction. Because the failure sits at the proxy layer, the consequences reach past the plug-in itself to the WebLogic backends behind it. Three Fusion Middleware releases are affected on Apache, and one on IIS.

Vulnerability details

Affected vendor
Oracle
Affected product
HTTP Server and Oracle Weblogic Server Proxy Plug-in
Weakness type (CWE)
CWE-284

CVE-2026-21962 is an improper access control flaw (CWE-284) in the WebLogic Server Proxy Plug-in component of Oracle HTTP Server, affecting versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. The plug-in, which fronts WebLogic backends from Apache HTTP Server or IIS, fails to enforce authorization checks on incoming HTTP requests. Because the access control boundary is not correctly applied at the proxy layer, unauthenticated network actors can reach protected resources without presenting credentials. The IIS variant is affected only at version 12.2.1.4.0; the Apache HTTP Server variant spans all three listed versions.


An attacker with network access to the Oracle HTTP Server or WebLogic Server Proxy Plug-in endpoint sends HTTP requests, with no credentials required, that the plug-in should reject but does not. Successful exploitation yields complete read access to all data the proxy plug-in can reach and full create, modify, or delete access to that same data. Because the CVSS scope is changed, the impact can extend beyond the plug-in itself to additional downstream products in the Fusion Middleware stack. No authentication, no user interaction, and no special configuration are required, making this trivially exploitable from any network position that can reach the HTTP listener.

Severity and impact

10.0
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality impact
High
Integrity impact
High
Availability impact
None

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review Oracle HTTP Server and IIS access logs for requests to protected backend paths that carry no authentication headers or session tokens and return 200-series responses, which would indicate the access control check was bypassed rather than enforced.
  • Audit proxy plug-in configuration and compare the list of protected URL patterns against actual request logs; requests reaching WebLogic backend resources without a corresponding authenticated session in the WebLogic server log are a strong indicator of exploitation.
  • Monitor for unexpected data modification events (file writes, record changes) in systems downstream of the proxy plug-in that do not correspond to any authenticated user session, which would reflect the integrity impact described in the vulnerability.

Remediation

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal (FCEB) remediation due date
August 27, 2026

Additional hardening

  • Apply the Oracle Critical Patch Update patches for the affected versions (12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0) as documented in the January 2026 Oracle Critical Patch Update advisory listed in References.
  • Restrict network access to Oracle HTTP Server and WebLogic Server Proxy Plug-in endpoints using perimeter controls, allowing only known, authorized source IP ranges to reach the HTTP listener rather than exposing it to broad network segments.
  • Place the proxy plug-in behind a web application firewall or reverse proxy configured to require authentication before forwarding requests, providing a compensating control while patching is in progress.
  • Audit and tighten the plug-in's URL routing and access control configuration to ensure that sensitive backend paths are explicitly protected, reducing the attack surface exposed through the proxy layer.

Key dates

Published (NVD)
January 20, 2026
Added to CISA KEV
August 24, 2026
Remediation deadline
August 27, 2026
Last updated
August 24, 2026

References

Frequently asked questions

Does CVE-2026-21962 affect my FedRAMP authorization?

If Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in operates inside your authorization boundary, yes, this affects your FedRAMP authorization. CVE-2026-21962 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, carrying a remediation deadline of August 27, 2026. An unpatched KEV within your boundary is a finding your assessor and sponsoring agency will raise. You must either remediate it or formally document a mitigation before that deadline arrives.

How does Knox help me handle CVE-2026-21962?

Knox does not patch Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in on your behalf. Under the FedRAMP shared-responsibility model, remediating CVE-2026-21962 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work is yours to execute; maintaining a compliant posture while you do it is not something you manage on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. When something like CVE-2026-21962 surfaces, exposure is identified through continuous monitoring rather than surfacing for the first time during an assessor review, giving you more time to act before it becomes a formal finding.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-21962 isn't remediated by August 27, 2026?

Missing the August 27, 2026 deadline turns CVE-2026-21962 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating on time keeps your authorization intact and the agency relationship straightforward.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting