CYBERSPACE / Pwning

CVE-2026-21962 – Weekly Pwning Pick

Oracle HTTP Server and WebLogic Server Proxy Plug-in improper access control vulnerability (CVSS 10.0) allows unauthenticated remote attackers to bypass authentication and gain full system access. Already under active exploitation with CISA deadline August 27, 2026.

CVE-2026-21962 represents a catastrophic security failure in Oracle's flagship middleware stack. The vulnerability exists in the WebLogic Server Proxy Plug-in for Apache HTTP Server and Microsoft IIS—critical bridge components that sit between client-facing HTTP servers and backend WebLogic application servers. The improper access control (CWE-284) flaw allows attackers with network-accessible HTTP endpoints to completely bypass authentication mechanisms. Technical breakdown: The vulnerability stems from insufficient validation of HTTP requests forwarded through the proxy plug-in. Attackers craft specialized HTTP requests that exploit the access control gap, gaining unauthorized entry to protected backend services without credentials. This is not a complex multi-step exploitation chain—the flaw is immediately exploitable via simple HTTP requests from unauthenticated actors. Impact is massive. Successful exploitation grants complete access to critical data stored in Oracle WebLogic environments, including the ability to create, modify, or delete mission-critical business data. The scope-change implication means compromised proxy components can pivot to internal systems. Organizations running Oracle HTTP Server versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0 are vulnerable. Active exploitation is confirmed. CISA's Intelligence and Analysis team detected exploitation attempts in March 2026 against honeypot networks. CloudSEK reported attackers combining CVE-2026-21962 with legacy WebLogic RCE flaws (CVE-2020-14882, CVE-2020-2551), suggesting mature threat actor playbooks. A China-linked threat group leveraged this flaw to compromise government and commercial infrastructure across 100+ countries, delivering the SNOWLIGHT downloader malware. The vulnerability was patched in Oracle's January 2026 CPU, but eight months later it remains actively exploited. CISA's Binding Operational Directive (BOD 26-04) mandates that Federal agencies patch by August 27, 2026. The 3-day deadline reflects the perfect-10 severity score and widespread exploitation—this is emergency-level response time for government infrastructure. Developers and security teams must prioritize immediate patching. Any internet-accessible Oracle middleware environment is potential attacker entry vector into critical backend systems.
Quelle ansehen ↗