Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.
Oracle's WebLogic Server Proxy Plug-in, which fronts WebLogic backends from Apache HTTP Server or IIS, fails to enforce authorization on incoming HTTP requests. An unauthenticated attacker with network access can reach protected resources and read, create, delete or modify the data the proxy can reach, with no credentials and no user interaction. Because the failure sits at the proxy layer, the consequences reach past the plug-in itself to the WebLogic backends behind it. Three Fusion Middleware releases are affected on Apache, and one on IIS.
CVE-2026-21962 is an improper access control flaw (CWE-284) in the WebLogic Server Proxy Plug-in component of Oracle HTTP Server, affecting versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. The plug-in, which fronts WebLogic backends from Apache HTTP Server or IIS, fails to enforce authorization checks on incoming HTTP requests. Because the access control boundary is not correctly applied at the proxy layer, unauthenticated network actors can reach protected resources without presenting credentials. The IIS variant is affected only at version 12.2.1.4.0; the Apache HTTP Server variant spans all three listed versions.
An attacker with network access to the Oracle HTTP Server or WebLogic Server Proxy Plug-in endpoint sends HTTP requests, with no credentials required, that the plug-in should reject but does not. Successful exploitation yields complete read access to all data the proxy plug-in can reach and full create, modify, or delete access to that same data. Because the CVSS scope is changed, the impact can extend beyond the plug-in itself to additional downstream products in the Fusion Middleware stack. No authentication, no user interaction, and no special configuration are required, making this trivially exploitable from any network position that can reach the HTTP listener.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in operates inside your authorization boundary, yes, this affects your FedRAMP authorization. CVE-2026-21962 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, carrying a remediation deadline of August 27, 2026. An unpatched KEV within your boundary is a finding your assessor and sponsoring agency will raise. You must either remediate it or formally document a mitigation before that deadline arrives.
Knox does not patch Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in on your behalf. Under the FedRAMP shared-responsibility model, remediating CVE-2026-21962 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work is yours to execute; maintaining a compliant posture while you do it is not something you manage on your own.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. When something like CVE-2026-21962 surfaces, exposure is identified through continuous monitoring rather than surfacing for the first time during an assessor review, giving you more time to act before it becomes a formal finding.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
Missing the August 27, 2026 deadline turns CVE-2026-21962 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating on time keeps your authorization intact and the agency relationship straightforward.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.









_Horizontal_RGB.png)









