CVE-2026-83062
moderateUnauthenticated LDAP Flaw Enables Full Takeover of Oracle Internet Directory
CVE-2026-83062 is a critical (CVSS 9.8) vulnerability in the OID LDAP Server component of Oracle Internet Directory, part of Oracle Fusion Middleware. An unauthenticated remote attacker with network access to the LDAP service can exploit it easily to compromise the Oracle Internet Directory instance, with high impact on confidentiality, integrity, and availability — effectively a complete takeover of the directory. Affected deployments are Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0. Because exploitation requires no credentials or user interaction and LDAP endpoints are often reachable across internal networks (and sometimes the internet), any exposed instance should be treated as high risk. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not on the CISA KEV list, but Oracle CPU flaws are frequently targeted once details circulate.
What to do: Apply the patch for CVE-2026-83062 from Oracle's Critical Patch Update via My Oracle Support as soon as it is available for your release track. Until patched, restrict network access to OID LDAP ports (389/636 and any admin ports) at the firewall so only trusted directory clients and controllers can connect, and avoid exposing LDAP services to the internet. Review logs for unauthenticated binds, anomalous directory modifications, or unexpected schema/configuration changes that could indicate compromise.
| Oracle Internet Directory (Oracle Fusion Middleware, OID LDAP Server component) | 12.2.1.4.0 |
| Oracle Internet Directory (Oracle Fusion Middleware, OID LDAP Server component) | 14.1.2.1.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.