Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2026-21962 — Proof-of-concept exploit for CVE-2026-21962, a critical path traversal vulnerability in Oracle OHS and WebLogic Server proxy plugins leading to privilege escalation and remote code execution. | Kitploit
Tools/GitHubGitHub/gregk4sec/cve-2026-21962
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHubgregk4sec/cve-2026-21962

cve-2026-21962

Proof-of-concept exploit for CVE-2026-21962, a critical path traversal vulnerability in Oracle OHS and WebLogic Server proxy plugins leading to privilege escalation and remote code execution.

View Repository
426 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Type: CVE Discoverer: gregk4sec Status: Public

CVE-2026-21962 — PATH-TRAVERSAL EOP / RCE DUE TO URI NORMALIZATION

Discoverer: gregk4sec (https://github.com/gregk4sec/cve)
Discovery Date: 2025-09-24
Affected Vendor: Oracle
Affected Product: Oracle OHS / Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS Severity: Critical / CVSS 10.0
CVSSv3.1 Base Score: 10.0
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
CWE: CWE-284 (Improper Access Control)
Status: Public


Summary

Path-Traversal EoP / RCE due to URI normalization inconsistency between Oracle OHS with default configuration and backend WebLogic server.


Technical Analysis

See:

analysis.md

Reproduction Steps

  1. Environment setup
  2. Trigger conditions
  3. Expected vs actual behavior
  4. Screenshots (optional)

Proof of Concept (PoC)

PoC files are located in:

root@kitploit:~
./poc/

Note: Some PoC content may be redacted or published later depending on disclosure requirements.


Disclosure Timeline

See: timeline.md


Vendor Response

See: ./vendor-response/


References

  • CVE Entry: CVE-2026-21962
  • Vendor Advisory: Oracle CPU
  • Security Bulletin: GHSA-4wp9-cf5h-v2g5
  • Related Research:

Attribution

This vulnerability is an original discovery by gregk4sec (https://github.com/gregk4sec/cve).
Repository: https://github.com/gregk4sec/cve

Download Tool