ZeroHour

CVE-2026-83062

moderate

Unauthenticated LDAP Flaw Enables Full Takeover of Oracle Internet Directory

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83062 is a critical (CVSS 9.8) vulnerability in the OID LDAP Server component of Oracle Internet Directory, part of Oracle Fusion Middleware. An unauthenticated remote attacker with network access to the LDAP service can exploit it easily to compromise the Oracle Internet Directory instance, with high impact on confidentiality, integrity, and availability — effectively a complete takeover of the directory. Affected deployments are Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0. Because exploitation requires no credentials or user interaction and LDAP endpoints are often reachable across internal networks (and sometimes the internet), any exposed instance should be treated as high risk. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not on the CISA KEV list, but Oracle CPU flaws are frequently targeted once details circulate.

What to do: Apply the patch for CVE-2026-83062 from Oracle's Critical Patch Update via My Oracle Support as soon as it is available for your release track. Until patched, restrict network access to OID LDAP ports (389/636 and any admin ports) at the firewall so only trusted directory clients and controllers can connect, and avoid exposing LDAP services to the internet. Review logs for unauthenticated binds, anomalous directory modifications, or unexpected schema/configuration changes that could indicate compromise.

Affected
Oracle Internet Directory (Oracle Fusion Middleware, OID LDAP Server component)12.2.1.4.0
Oracle Internet Directory (Oracle Fusion Middleware, OID LDAP Server component)14.1.2.1.0
Estimated exposure
moderatelikely on the order of a few thousand internet-reachable instances, with a larger internal-only installed base (estimate) — Oracle Internet Directory is enterprise identity middleware typically deployed inside corporate networks as part of Fusion Middleware environments; public internet scans cannot reliably fingerprint OID among generic LDAP (389/636)…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.