EXPOSURES › CVE-2026-21962
CVE-2026-21962
HIGH ⌖ ON CISA KEV · EXPLOITEDOracle HTTP Server and Weblogic Server Proxy Plug-in suffer from an improper access control flaw allowing unauthorized data manipulation and full data access.
This improper access control vulnerability in Oracle HTTP Server and Weblogic Server Proxy Plug-in allows attackers to create, delete, or modify critical data and gain complete access to all accessible data. For DIB organizations, this means unpatched Oracle infrastructure could lead to massive data breaches and compliance failures under NIST 800-171. Organizations must immediately patch Oracle HTTP Server and Weblogic Server Proxy Plug-in to prevent unauthorized data exposure and maintain compliance.
Shame score — A high-severity improper access control flaw in widely deployed Oracle products that allows complete data access and manipulation, representing a negligent failure to secure critical infrastructure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |