CVE intelligence
CVE-2026-21962
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
Oracle · Published 2026-01-20 · CVSS CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Changed
CConfidentiality- High
IIntegrity- High
AAvailability- None
critical · KEV listed 2026-08-24 · Action due 2026-08-27
NIST record