CVE-2026-83057
moderateLow-Privilege LDAP Takeover Flaw in Oracle Internet Directory (CVSS 9.9)
A critical vulnerability in the OID LDAP Server component of Oracle Internet Directory, part of Oracle Fusion Middleware, allows a low-privileged attacker with network access via LDAP to fully compromise the directory service. The flaw requires only an authenticated (low-privilege) LDAP connection and no user interaction, and because of a scope change, successful attacks can significantly impact additional products beyond Oracle Internet Directory itself. Successful exploitation results in a complete takeover of Oracle Internet Directory with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 9.9). Affected deployments are Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0. No public proof-of-concept exists, the issue is not in the CISA Known Exploited Vulnerabilities catalog, and no exploitation in the wild has been reported.
What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83057 to Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0 deployments as soon as it is available. Restrict LDAP (ports 389/636) access at the network layer to only trusted clients and management hosts, and audit low-privilege LDAP bind accounts for unnecessary access. Review LDAP and OID server logs for anomalous bind, search, and modify activity from low-privilege accounts as an indicator of attempted exploitation.
| Oracle Internet Directory (Oracle Fusion Middleware, component: OID LDAP Server) | 12.2.1.4.0, 14.1.2.1.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.