ZeroHour

CVE-2026-83056

moderate

Low-Privilege LDAP Flaw Allows Full Takeover of Oracle Internet Directory (CVSS 9.9)

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

A critical vulnerability in the OID LDAP Server component of Oracle Internet Directory, part of Oracle Fusion Middleware, allows a low-privileged attacker with network access via LDAP to fully compromise the Oracle Internet Directory deployment. The flaw is rated as easily exploitable, requires only an authenticated low-privilege LDAP connection and no user interaction, and carries a scope change, meaning successful attacks can significantly impact additional products beyond Oracle Internet Directory itself. Successful exploitation results in a complete takeover of the directory service with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 9.9). The affected versions are Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0. No public proof-of-concept exists and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog, so no exploitation in the wild is currently known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83056 to Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0 as soon as it is available for your release track. In the interim, restrict LDAP network access to trusted clients and VPN ranges, audit and lock down low-privilege bind and service accounts, and monitor LDAP logs for anomalous authenticated activity. Because of the scope change, also review integrated Fusion Middleware products that trust OID for authentication.

Affected
Oracle Internet Directory (Oracle Fusion Middleware, component: OID LDAP Server)12.2.1.4.0
Oracle Internet Directory (Oracle Fusion Middleware, component: OID LDAP Server)14.1.2.1.0
Estimated exposure
moderateLikely on the order of thousands of enterprise OID installations (1k–10k), predominantly internal LDAP services — Oracle Internet Directory is licensed enterprise middleware with no public install counts, and internet-wide scan data typically shows only a small number of exposed Oracle LDAP endpoints because directories are usually deployed on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.