
Proof-of-concept exploit for CVE-2026-21962, a critical path traversal vulnerability in Oracle OHS and WebLogic Server proxy plugins leading to privilege escalation and remote code execution.
Discoverer: gregk4sec (https://github.com/gregk4sec/cve)
Discovery Date: 2025-09-24
Affected Vendor: Oracle
Affected Product: Oracle OHS / Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS
Severity: Critical / CVSS 10.0
CVSSv3.1 Base Score: 10.0
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
CWE: CWE-284 (Improper Access Control)
Status: Public
Path-Traversal EoP / RCE due to URI normalization inconsistency between Oracle OHS with default configuration and backend WebLogic server.
analysis.mdPoC files are located in:
./poc/
Note: Some PoC content may be redacted or published later depending on disclosure requirements.
See: timeline.md
See: ./vendor-response/
This vulnerability is an original discovery by gregk4sec (https://github.com/gregk4sec/cve).
Repository: https://github.com/gregk4sec/cve