CVE-2026-21962

CRITICAL EXPLOITED

Oracle HTTP Server & WebLogic Proxy Plug-in 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0 - Unauthenticated Access Control

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2026-21962 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 9 public exploits from researchers including XiaomingX, samael0x4, George0Papasotiriou.

AI-analyzed exploit summary The repository lacks exploit code and provides no technical details about CVE-2026-21962. The README contains vague claims and a message about delaying PoC release, which is a common tactic in suspicious repos.

Description

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

Exploits (9)

github SUSPICIOUS 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-21962

The repository lacks exploit code and provides no technical details about CVE-2026-21962. The README contains vague claims and a message about delaying PoC release, which is a common tactic in suspicious repos.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in
No auth needed
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec SCANNER 3 stars
by samael0x4 · poc
https://github.com/samael0x4/CVE-2026-21962

This repository contains a detection tool for CVE-2026-21962, which targets Oracle HTTP Server and WebLogic Proxy Plug-in. The Python script performs passive detection by checking HTTP response headers for specific patterns associated with vulnerable versions.

Classification
Scanner 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Oracle HTTP Server 12.2.1.4.0, WebLogic Proxy Plug-in 12.2.1.4.0/14.1.1.0.0/14.1.2.0.0
No auth needed
Prerequisites: Network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SCANNER 2 stars
by George0Papasotiriou · poc
https://github.com/George0Papasotiriou/CVE-2026-21962-Oracle-HTTP-Server-WebLogic-Proxy-Plug-in-Critical-

The repository contains a scanner and exploit simulator for CVE-2026-21962, targeting Oracle HTTP Server WebLogic Proxy Plug-in. It probes for vulnerable endpoints and simulates exploit patterns without executing actual malicious payloads.

Classification
Scanner 90%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: Oracle HTTP Server WebLogic Proxy Plug-in
No auth needed
Prerequisites: Network access to the target server · Oracle HTTP Server with WebLogic Proxy Plug-in
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 2 stars
by boroeurnprach · poc
https://github.com/boroeurnprach/Ashwesker-CVE-2026-21962

This is a functional PoC for CVE-2026-21962, an unauthenticated RCE vulnerability in Oracle WebLogic Server Proxy Plug-In. It exploits a deserialization/command injection flaw via crafted headers and URIs.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle HTTP Server / WebLogic Proxy Plug-In < 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0
No auth needed
Prerequisites: Network access to vulnerable Oracle HTTP Server/WebLogic Proxy Plug-In · Exposed proxy plug-in endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
github WRITEUP
by 0xBlackash · remote
https://github.com/0xBlackash/CVE-2026-21962

This repository provides a detailed technical analysis of CVE-2026-21962, an authentication bypass vulnerability in Oracle HTTP Server and WebLogic Proxy Plug-in. It includes affected versions, mitigation strategies, and detection indicators but lacks functional exploit code.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Theoretical
Target: Oracle HTTP Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0), WebLogic Proxy Plug-in (Apache/IIS)
No auth needed
Prerequisites: Network access to vulnerable Oracle middleware systems
devstral-2 · analyzed Apr 24, 2026 Full analysis →
nomisec WORKING POC
by naozibuhao · poc
https://github.com/naozibuhao/CVE-2026-21962_Java_GUI_Exploit_Tool

This repository contains a functional Java GUI exploit tool for CVE-2026-21962, targeting Oracle WebLogic Server Proxy Plug-In RCE. The tool automates testing multiple vulnerable paths and executes arbitrary commands via crafted HTTP headers.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server Proxy Plug-In (versions < patched 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0)
No auth needed
Prerequisites: Network access to vulnerable WebLogic server · Exposed Proxy Plug-In endpoint
devstral-2 · analyzed Mar 21, 2026 Full analysis →
nomisec SUSPICIOUS
by gregk4sec · poc
https://github.com/gregk4sec/CVE-2026-21962-o

The repository lacks any technical details or exploit code, instead using vague marketing language and promising a future PoC release. No actual vulnerability analysis or proof-of-concept is provided.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in
No auth needed
Prerequisites: network access via HTTP
devstral-2 · analyzed Mar 08, 2026 Full analysis →
nomisec WRITEUP
by gregk4sec · poc
https://github.com/gregk4sec/CVE-2026-21962

This repository contains a README describing CVE-2026-21962, a critical vulnerability (CVSS 10.0) in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. The author mentions it is easily exploitable via HTTP but has not yet released a PoC.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Oracle HTTP Server, Oracle WebLogic Server Proxy Plug-in
No auth needed
Prerequisites: Network access via HTTP
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by ThumpBo · poc
https://github.com/ThumpBo/CVE-2026-21962

This is a functional PoC exploit for CVE-2026-21962, targeting a WebLogic Proxy Plug-In RCE vulnerability. It leverages base64-encoded command injection via HTTP headers to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle WebLogic Server (specific version not specified)
No auth needed
Prerequisites: Network access to the target WebLogic server · Vulnerable WebLogic Proxy Plug-In endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 10.0
EPSS 0.0002
EPSS Percentile 6.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2026-02-10
CWE
CWE-284
Status published
Products (6)
oracle/http_server 12.2.1.4.0
oracle/http_server 14.1.1.0.0
oracle/http_server 14.1.2.0.0
oracle/weblogic_server_proxy_plug-in 12.2.1.4.0
oracle/weblogic_server_proxy_plug-in 14.1.1.0.0
oracle/weblogic_server_proxy_plug-in 14.1.2.0.0
Published Jan 20, 2026
Tracked Since Feb 18, 2026