Security
Loading…

CVE-2026-21962

CRITICALCVSS 10.0Known Exploited
Description

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.

Timeline
Published:January 20th, 2026 10:15 PM
Last modified:August 25th, 2026 4:18 AM
Added to KEV:August 24th, 2026
CVSS Scoring

CVSS v3: 10.0 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Affected Software
From NVD CPE configuration data

Vendors

oracle

Products

http_serverweblogic_server_proxy_plug-in
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute