ZeroHour

CVE-2026-83054

moderate

Unauthenticated LDAP Takeover Flaw in Oracle Internet Directory (CVSS 9.8)

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83054 is a critical (CVSS 9.8) vulnerability in the OID LDAP Server component of Oracle Internet Directory, part of Oracle Fusion Middleware. An unauthenticated attacker with network access to the LDAP service can exploit the flaw easily, and a successful attack results in a complete takeover of the Oracle Internet Directory instance, with high impact on confidentiality, integrity, and availability. Affected supported versions are 12.2.1.4.0 and 14.1.2.1.0, meaning organizations running either the 12c or 14c release lines are exposed. Because OID typically serves as an enterprise identity and directory backbone, compromise could cascade into broader identity infrastructure. No public proof of concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation in the wild is not currently observed.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83054 to all Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0 instances, prioritizing any listener reachable beyond a trusted subnet. Restrict network access to the OID LDAP ports (typically the non-SSL and SSL LDAP listeners) to only directory clients and administration hosts. Review OID logs and directory data for unexplained entry modifications, new privileged binds, or schema changes that could indicate prior probing or compromise.

Affected
Oracle Internet Directory (Oracle Fusion Middleware, component: OID LDAP Server)12.2.1.4.0
Oracle Internet Directory (Oracle Fusion Middleware, component: OID LDAP Server)14.1.2.1.0
Estimated exposure
moderate≈1,000–10,000 installations (order of magnitude), mostly internal enterprise deployments — Oracle Internet Directory is an enterprise identity-management product licensed per deployment rather than a mass-market tool, and public internet scans fingerprint relatively few internet-exposed OID LDAP endpoints, with the bulk of the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.