CVE-2026-83060
moderateUnauthenticated LDAP Flaw Enables Full Takeover of Oracle Internet Directory
CVE-2026-83060 is a critical (CVSS 9.8) vulnerability in the OID LDAP Server component of Oracle Internet Directory, part of Oracle Fusion Middleware. An unauthenticated attacker who can reach the LDAP service over the network can exploit it easily and without user interaction, and a successful attack results in complete takeover of the Oracle Internet Directory instance, with high impact on confidentiality, integrity, and availability. Affected deployments are those running the supported versions 12.2.1.4.0 or 14.1.2.1.0. Because OID typically serves as an enterprise identity and directory backend, a compromise could cascade into broader authentication and access-control abuse across dependent systems. There is no known public proof-of-concept and the flaw is not on the CISA Known Exploited Vulnerabilities list, so exploitation in the wild is not currently evidenced.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83060 to all Oracle Internet Directory instances on 12.2.1.4.0 or 14.1.2.1.0 as a top priority. Until patched, restrict network access to the OID LDAP ports (389/636 and any admin listeners) to trusted sources only via firewall or ACLs. Review LDAP authentication and directory logs for anomalous or unauthenticated activity indicative of compromise.
| Oracle Internet Directory (Oracle Fusion Middleware, component: OID LDAP Server) | 12.2.1.4.0 |
| Oracle Internet Directory (Oracle Fusion Middleware, component: OID LDAP Server) | 14.1.2.1.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.