CVE-2026-21962
Weblogic Server Proxy Plug-in for Apache HTTP Server vulnerability analysis and mitigation

Overview

CVE-2026-21962 is a maximum-severity improper access control vulnerability (CWE-284) in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, components of Oracle Fusion Middleware. It affects versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 (note: the IIS plug-in variant is only affected in version 12.2.1.4.0). The vulnerability was disclosed on January 20, 2026, as part of Oracle's January 2026 Critical Patch Update, which addressed 337 vulnerabilities in total. It carries a CVSS v3.1 base score of 10.0 (Critical), reflecting its unauthenticated, network-exploitable, scope-changing nature (Oracle CPU Jan 2026, Feedly).

Technical details

The root cause is improper access control (CWE-284) in the WebLogic Server Proxy Plug-in for both Apache HTTP Server and Microsoft IIS. An unauthenticated attacker with network access via HTTP can exploit this flaw without any user interaction or special privileges, making it trivially exploitable. The vulnerability has a scope change, meaning successful exploitation can impact additional Oracle Fusion Middleware products beyond the directly affected proxy plug-in component. Multiple public proof-of-concept scripts have been published on GitHub (e.g., Ashwesker-CVE-2026-21962, samael0x4/CVE-2026-21962, ThumpBo/CVE-2026-21962, gregk4sec/CVE-2026-21962), and Nuclei templates have been submitted for automated detection (Oracle CPU Jan 2026, SANS ISC, Feedly).

Impact

Successful exploitation allows an unauthenticated remote attacker to perform unauthorized creation, deletion, or modification of critical data accessible to Oracle HTTP Server and WebLogic Server Proxy Plug-in, as well as complete unauthorized read access to all such data — resulting in total loss of confidentiality and integrity (CVSS Availability impact is None). Due to the scope change, attacks can cascade to additional Oracle Fusion Middleware products beyond the directly compromised component, significantly amplifying the blast radius. CloudSEK's honeypot research confirmed active attacker interest in these WebLogic proxy vulnerabilities, with exploitation observed within hours of public PoC release (CloudSEK Honeypot, GBHackers).

Exploitation steps

  1. Reconnaissance: Use Shodan, Censys, or FOFA to identify internet-facing Oracle HTTP Server or WebLogic Server Proxy Plug-in instances running versions 12.2.1.4.0, 14.1.1.0.0, or 14.1.2.0.0. Look for characteristic HTTP response headers or banners associated with Oracle Fusion Middleware.
  2. PoC Acquisition: Obtain one of the publicly available PoC scripts from GitHub repositories (e.g., Ashwesker/Ashwesker-CVE-2026-21962, samael0x4/CVE-2026-21962, or ThumpBo/CVE-2026-21962). Nuclei templates have also been submitted for automated scanning.
  3. Exploit Delivery: Send a crafted unauthenticated HTTP request to the vulnerable proxy plug-in endpoint. The improper access control flaw allows the request to bypass authentication and authorization checks entirely.
  4. Data Access/Manipulation: Leverage the access control bypass to read, create, delete, or modify critical data accessible to the Oracle HTTP Server or WebLogic Proxy Plug-in service account, potentially including configuration files, application data, or credentials.
  5. Lateral Movement: Exploit the scope change characteristic of the vulnerability to pivot into additional Oracle Fusion Middleware components accessible through the compromised proxy, expanding the attack surface beyond the initial target (SANS ISC, Field Effect, Oracle CPU Jan 2026).

Indicators of compromise

  • Network: Unusual or malformed HTTP requests to Oracle HTTP Server or WebLogic Proxy Plug-in endpoints from unexpected source IPs; outbound connections from the server to unknown external hosts following inbound HTTP requests; scanning activity from single IPs probing WebLogic proxy endpoints at high frequency.
  • Logs: Oracle HTTP Server access logs showing unauthenticated requests to proxy plug-in endpoints resulting in unexpected 200 responses or data modification; error logs showing access control bypass conditions; SANS ISC noted "odd WebLogic requests" in HTTP logs consistent with exploit attempts as of January 28, 2026.
  • File System: Unexpected new files or modified configuration files in Oracle HTTP Server or WebLogic installation directories; web shells or backdoors dropped in accessible web roots; unauthorized changes to proxy plug-in configuration files.
  • Process: Unusual child processes spawned by the Oracle HTTP Server or WebLogic proxy process; unexpected network connections initiated by the Oracle service account; evidence of data exfiltration tools (e.g., curl, wget) executed under the Oracle service context (SANS ISC, CloudSEK Honeypot).

Mitigation and workarounds

Oracle released patches for CVE-2026-21962 as part of the January 2026 Critical Patch Update (CPU); organizations should apply the relevant Fusion Middleware patches for versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 immediately via the Oracle patch delivery mechanism. Until patches are applied, restrict network access to affected Oracle HTTP Server and WebLogic Proxy Plug-in instances via firewall rules, limiting HTTP access to only authorized and trusted systems. Implement network segmentation to isolate Fusion Middleware components, monitor HTTP traffic for anomalous requests to proxy plug-in endpoints, and consider disabling the WebLogic Server Proxy Plug-in for Apache HTTP Server or IIS if not operationally required. Oracle strongly recommends customers remain on actively supported versions and apply CPU patches without delay (Oracle CPU Jan 2026, Arctic Wolf).

Community reactions

The vulnerability generated significant attention across the security community immediately after disclosure. Arctic Wolf, Field Effect, Imperva, Sangfor, Fortinet (FortiWeb/FortiAppSec), and Check Point all published advisories or confirmed protection for their customers (Arctic Wolf, Field Effect, Imperva via Security Boulevard). SANS ISC published a diary entry on January 28, 2026, documenting "odd WebLogic requests" that may represent early exploitation attempts or AI-generated exploit noise, sparking community debate (SANS ISC). National CERTs including Canada (CCCS), Belgium (CCB), Singapore (CSA), Ireland (NCSC-IE), and Australia (WA SOC) issued advisories urging immediate patching. The Hacker News, BleepingComputer, and multiple security outlets covered the vulnerability as part of broader Oracle CPU coverage, and the CVSS 10.0 score drew widespread social media commentary on Mastodon, Bluesky, and Reddit.

Additional resources


SourceThis report was generated using AI

Related Weblogic Server Proxy Plug-in for Apache HTTP Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-60365CRITICAL10
  • Weblogic Server Proxy Plug-in for Apache HTTP Server logoWeblogic Server Proxy Plug-in for Apache HTTP Server
  • cpe:2.3:a:oracle:weblogic_server_proxy_plug-in
NoNoJul 21, 2026
CVE-2026-21962CRITICAL10
  • Weblogic Server Proxy Plug-in for Apache HTTP Server logoWeblogic Server Proxy Plug-in for Apache HTTP Server
  • cpe:2.3:a:oracle:weblogic_server_proxy_plug-in
NoNoJan 20, 2026
CVE-2026-60364CRITICAL9.8
  • Weblogic Server Proxy Plug-in for Apache HTTP Server logoWeblogic Server Proxy Plug-in for Apache HTTP Server
  • cpe:2.3:a:oracle:weblogic_server_proxy_plug-in
NoNoJul 21, 2026
CVE-2020-35169CRITICAL9.8
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database
NoYesJul 11, 2022
CVE-2020-35168CRITICAL9.8
  • Oracle Database Server logoOracle Database Server
  • cpe:2.3:a:oracle:database
NoYesJul 11, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management