ZeroHour

CVE-2026-83061

niche

Unauthenticated LDAP Flaw Enables Full Takeover of Oracle Internet Directory

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83061 is a critical (CVSS 9.8) vulnerability in the OID LDAP Server component of Oracle Internet Directory, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. An unauthenticated remote attacker who can reach the LDAP service over the network can exploit the flaw with low complexity, requiring no privileges or user interaction. A successful attack can result in complete takeover of Oracle Internet Directory, with high impact on confidentiality, integrity, and availability of the directory service. Because OID often stores and authenticates enterprise identity data, compromise could cascade into broader access to dependent applications and middleware. The flaw is not currently listed in CISA's KEV catalog and no public proof-of-concept is known, but Oracle's track record of similar directory-service bugs makes patching urgent.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83061 to all Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0 installations. Until patched, restrict network access to LDAP ports (typically 389/636) to only trusted clients and management hosts, and consider blocking internet-facing exposure entirely. Review OID logs for unexplained binds, schema or administrative changes, and replication anomalies that could indicate compromise.

Affected
Oracle Internet Directory (Oracle Fusion Middleware, OID LDAP Server component)12.2.1.4.0, 14.1.2.1.0
Estimated exposure
nichelikely low thousands of enterprise deployments worldwide, with an unknown subset internet-exposed — Oracle Internet Directory is an enterprise middleware component licensed to a subset of Oracle Fusion Middleware customers rather than a mass-market product, and LDAP directories are typically deployed on internal networks, so I estimate a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.