CVE-2026-83054
moderateUnauthenticated LDAP Takeover Flaw in Oracle Internet Directory (CVSS 9.8)
CVE-2026-83054 is a critical (CVSS 9.8) vulnerability in the OID LDAP Server component of Oracle Internet Directory, part of Oracle Fusion Middleware. An unauthenticated attacker with network access to the LDAP service can exploit the flaw easily, and a successful attack results in a complete takeover of the Oracle Internet Directory instance, with high impact on confidentiality, integrity, and availability. Affected supported versions are 12.2.1.4.0 and 14.1.2.1.0, meaning organizations running either the 12c or 14c release lines are exposed. Because OID typically serves as an enterprise identity and directory backbone, compromise could cascade into broader identity infrastructure. No public proof of concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation in the wild is not currently observed.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83054 to all Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0 instances, prioritizing any listener reachable beyond a trusted subnet. Restrict network access to the OID LDAP ports (typically the non-SSL and SSL LDAP listeners) to only directory clients and administration hosts. Review OID logs and directory data for unexplained entry modifications, new privileged binds, or schema changes that could indicate prior probing or compromise.
| Oracle Internet Directory (Oracle Fusion Middleware, component: OID LDAP Server) | 12.2.1.4.0 |
| Oracle Internet Directory (Oracle Fusion Middleware, component: OID LDAP Server) | 14.1.2.1.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.