{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-21962",
  "revision": 1,
  "title": "Oracle WebLogic Proxy Plug-in — Unauthenticated Access Control Bypass",
  "summary": "Oracle's web server and the WebLogic proxy plug-in it hosts fail to check access on some requests, so anyone who can reach them over the network can read, change or delete data they should never see, and the damage can spread to the applications proxied behind them.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 10,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
    "version": "3.1"
  },
  "epss": 0.42475,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-08-24",
    "prerequisites": "Network access to an Oracle web server running the WebLogic proxy plug-in"
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Apply Oracle's Critical Patch Update to Oracle HTTP Server and the WebLogic proxy plug-in, or block outside access to the proxy until you can.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-21962",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-21962",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-21962",
      "retrieved_at": "2026-09-21T07:05:11.841Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21962",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://www.oracle.com/security-alerts/cpujan2026.html"
    }
  ],
  "published_at": "2026-01-20T22:15:59.110Z",
  "issued_at": "2026-09-21T07:05:11.841Z",
  "tags": [
    "oracle",
    "weblogic",
    "web-server",
    "access-control"
  ]
}
