ZeroHour

CVE-2026-83058

moderate

Critical Low-Privilege LDAP Takeover Flaw in Oracle Internet Directory

CVSS 3.1
9.9 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83058 is a critical (CVSS 9.9) vulnerability in the OID LDAP Server component of Oracle Internet Directory, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. A remote attacker with only low-privileged network access via LDAP can exploit it easily (no user interaction required), and because of a scope change, a successful attack can also significantly impact additional products beyond Oracle Internet Directory itself. Successful exploitation results in complete takeover of Oracle Internet Directory, with high impact on confidentiality, integrity, and availability of the directory service and the identity data it holds. Organizations running the affected OID versions as their LDAP/identity backbone are the primary victims, with downstream impact possible for any applications relying on the directory for authentication. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild is currently known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83058 to affected 12.2.1.4.0 and 14.1.2.1.0 deployments as soon as possible. Restrict LDAP (389/636 and admin ports) to trusted networks and VPNs, and tightly audit or prune low-privileged LDAP bind accounts that could serve as the entry point. Review directory logs for anomalous modifications, privilege changes, or new administrative entries on OID instances, and assess dependent applications given the potential scope change.

Affected
Oracle Internet Directory (Oracle Fusion Middleware, component: OID LDAP Server)12.2.1.4.0, 14.1.2.1.0
Estimated exposure
moderatelikely thousands of enterprise deployments worldwide (exact count unknown) — Oracle Internet Directory is enterprise identity-infrastructure software with no public install counts, but it is deployed by a subset of large Oracle Fusion Middleware customers, typically a few instances per organization, most of them…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.