Junglewise Threat Intelligence

CVE-2026-21962: Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in improper access control

CVE-2026-21962 · Severity: critical · Exploited in the wild · Published 2026-08-24

Executive brief

Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, used to route and proxy web requests to backend Oracle servers, contain an improper access control vulnerability that allows attackers to bypass authentication or authorization controls. An attacker could create, delete, or modify critical data, or gain unauthorized access to sensitive information without proper credentials. This vulnerability has been actively exploited in the wild.

Technical details

This is an improper access control vulnerability in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in that allows attackers to bypass authentication or authorization mechanisms. The vulnerability affects the proxy plug-in component responsible for routing requests between the HTTP Server and backend WebLogic servers. An attacker with network access to an affected proxy can exploit this flaw without requiring valid credentials or user interaction, enabling unauthorized CRUD operations on critical data and complete information disclosure. The vulnerability has been actively exploited in the wild, indicating proof-of-concept or weaponized exploits exist in attacker toolkits.

Affected products

  • Oracle HTTP Server
  • Oracle WebLogic Server Proxy Plug-in

Timeline

  • 2026-08-24: disclosed
  • exploited: Known to be actively exploited in the wild

Related threats