CVE-2026-83059
moderateUnauthenticated LDAP Flaw Allows Full Takeover of Oracle Internet Directory
CVE-2026-83059 is a critical (CVSS 10.0) vulnerability in the OID LDAP Server component of Oracle Internet Directory, part of Oracle Fusion Middleware, affecting supported versions 12.2.1.4.0 and 14.1.2.1.0. An unauthenticated remote attacker with network access to the LDAP service can exploit the flaw with low complexity, requiring no privileges or user interaction. Successful exploitation results in a complete takeover of Oracle Internet Directory with high impact to confidentiality, integrity, and availability, and because the scope changes, successful attacks may also significantly impact additional products beyond OID itself. Organizations running the affected OID versions with LDAP reachable by untrusted networks are the primary at-risk population. No public proof of concept is known, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported to date.
What to do: Apply the Oracle Critical Patch Update that remediates this vulnerability to all Oracle Internet Directory instances running 12.2.1.4.0 or 14.1.2.1.0, prioritizing any OID LDAP endpoints reachable from untrusted networks. Restrict network access to OID LDAP ports so only trusted directory clients can connect, and verify no unauthenticated anomalous LDAP activity has occurred on affected servers.
| Oracle Internet Directory (Oracle Fusion Middleware, OID LDAP Server component) | 12.2.1.4.0, 14.1.2.1.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.