ZeroHour

CVE-2026-83055

moderate

Low-Privilege LDAP Flaw Enables Full Takeover of Oracle Internet Directory

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

Oracle Internet Directory's LDAP Server component (part of Oracle Fusion Middleware) contains an easily exploitable vulnerability rated CVSS 3.1 9.9 (CVE-2026-83055). It is triggered when a low-privileged attacker with network access to the LDAP service exploits the flaw, requiring no user interaction. Successful attacks result in complete takeover of Oracle Internet Directory with high impact to confidentiality, integrity, and availability, and — because the CVSS scope is 'changed' — the blast radius can extend to additional products beyond OID itself. Affected deployments are Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0. No public proof-of-concept is known, the CVE is not on CISA's KEV, and no exploitation in the wild has been reported to date.

What to do: Apply Oracle's Critical Patch Update fixes covering CVE-2026-83055 to Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0 as soon as they are available. Restrict the OID LDAP listener ports (e.g., 3060/3131, or 389/636) to trusted application and management networks via firewall rules, since exploitation requires network access to LDAP. Audit low-privileged directory accounts for compromise and monitor LDAP logs for anomalous binds, schema/configuration changes, or privilege escalation originating from unprivileged DNs.

Affected
Oracle Internet Directory (Oracle Fusion Middleware, component: OID LDAP Server)
Estimated exposure
moderateLikely a few thousand internet-exposed OID LDAP services; additional tens of thousands of internal enterprise deployments (order-of-magnitude estimate) — Estimated from public internet-wide scan patterns showing that only a small fraction of exposed LDAP listeners (ports 389/636/3060/3131) identify as Oracle directory products, since OID is typically deployed as internal corporate…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.