Oracle HTTP Server and WebLogic proxy plug-in access control flaw (CVE-2026-21962) — listed the year it was found, three days to fix
A component that hands web requests through to a business application platform is recorded as not applying access control properly. Numbering and listing fell in the same year, three days were allowed, and the required action goes beyond applying updates to naming a prioritization directive and requirements for preserving records.
Key facts
- CVE IDCVE-2026-21962
- Affected (vendor / product)Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in
- CWECWE-284
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2026-08-27 (U.S. federal civilian agencies, BOD 22-01)
Key points
- A proxy component handing web requests to a business application platform is recorded as not applying access control properly (CWE-284).
- Important data may be created, deleted or altered without authorization, and everything reachable through the component may become reachable.
- Added 24 August 2026 and due 27 August 2026, an allowance of three days, with numbering and listing in the same year.
- The required action covers not only updates but observance of a prioritization directive, requirements for preserving records, and responsibility for judging exposure.
- Only 101 of the 1,694 records this site holds as of 2026-09-04 (6.0%) allow three days or less, and 85.1% of those were numbered and listed in the same year.
1A component that hands things through
A web server takes requests from users and passes some of them back to the business application platform behind it. What is affected here is the component that does the handing through. It is invisible from the front and its name rarely comes up. Yet because it touches both sides, access control failing there opens a path to whatever sits behind.
The catalog describes important data being created, deleted or altered without authorization, and everything reachable through the component becoming reachable.
2Not finished at apply the update
Most entries end with a single line about applying vendor updates. This one does not. A directive for ordering work by risk is named, requirements for preserving records are set alongside it, and responsibility for judging exposure is written down.
The same phrasing turns up again in the eighteen-year-old entry at the end of this series. How the required action is written reflects both the weight of an entry and what is happening now.
3Three days
The median allowance is 21 days, a value shared by 1,025 entries. Three days or less is rare, and most of that group reached the catalog within the year the identifier was issued. A short deadline, in other words, usually attaches to something happening now. As later articles show, there are exceptions.
4What it means to be listed in the year it was found
Of the 1,694 records this site holds as of 2026-09-04, 731 (43.2%) reached the catalog in the same year their identifier was issued, the largest group. Little time passed between disclosure and confirmed exploitation. Attackers read the same publications, so publication and exploitation converge. The articles that follow walk out along that interval as it widens to one year, three, seven, and eighteen.
Why it matters
The components that hand things through are invisible from the front and touch both sides at once. Access control failing there opens the path to whatever sits behind. When a required action runs past a single line into directives, record preservation and responsibility for judging exposure, it signals preparation for something that may already have happened, not merely the availability of a fix.
FAQ
What is a proxy plug-in?
Why only three days?
Is applying an update enough?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).