ZeroHour

CVE-2026-83059

moderate

Unauthenticated LDAP Flaw Allows Full Takeover of Oracle Internet Directory

CVSS 3.1
10.0 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83059 is a critical (CVSS 10.0) vulnerability in the OID LDAP Server component of Oracle Internet Directory, part of Oracle Fusion Middleware, affecting supported versions 12.2.1.4.0 and 14.1.2.1.0. An unauthenticated remote attacker with network access to the LDAP service can exploit the flaw with low complexity, requiring no privileges or user interaction. Successful exploitation results in a complete takeover of Oracle Internet Directory with high impact to confidentiality, integrity, and availability, and because the scope changes, successful attacks may also significantly impact additional products beyond OID itself. Organizations running the affected OID versions with LDAP reachable by untrusted networks are the primary at-risk population. No public proof of concept is known, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported to date.

What to do: Apply the Oracle Critical Patch Update that remediates this vulnerability to all Oracle Internet Directory instances running 12.2.1.4.0 or 14.1.2.1.0, prioritizing any OID LDAP endpoints reachable from untrusted networks. Restrict network access to OID LDAP ports so only trusted directory clients can connect, and verify no unauthenticated anomalous LDAP activity has occurred on affected servers.

Affected
Oracle Internet Directory (Oracle Fusion Middleware, OID LDAP Server component)12.2.1.4.0, 14.1.2.1.0
Estimated exposure
moderate≈ a few thousand internet-exposed OID LDAP endpoints, out of a larger base of roughly tens of thousands of internal enterprise deployments (clearly an estimate) — Oracle Internet Directory is enterprise middleware typically deployed internally alongside Oracle Fusion applications and rarely exposed to the public internet, so the exposure basis is deployment patterns and typical scan visibility of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.