ZeroHour

CVE-2026-83066

moderate

Unauthenticated Takeover of Oracle Internet Directory via T3/IIOP

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83066 is a critical (CVSS 9.8) vulnerability in the OID LDAP Server component of Oracle Internet Directory, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. An unauthenticated remote attacker who can reach the server over the network via the T3 or IIOP protocols can exploit the flaw without any privileges or user interaction, and a successful attack can result in a complete takeover of the Oracle Internet Directory instance with high impact on confidentiality, integrity, and availability. Because OID often serves as a central LDAP/directory service, compromise could expose or allow manipulation of directory data and credentials relied on by downstream enterprise applications. Organizations running the affected OID versions with T3/IIOP listeners reachable by untrusted networks are at greatest risk. As of now, the flaw is not in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so exploitation status is none known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83066 to all Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0 deployments. Until patched, block or strictly limit T3 and IIOP access at the firewall and via WebLogic connection filters so only trusted administrator hosts can reach those protocols. Review directory server logs for unauthenticated T3/IIOP connection attempts and unexpected administrative changes as indicators of attempted compromise.

Affected
Oracle Internet Directory (Fusion Middleware, OID LDAP Server component)
Estimated exposure
moderatelikely low thousands of internet-reachable T3/IIOP endpoints, with thousands more OID deployments on internal enterprise networks — Oracle Internet Directory is enterprise-only middleware typically deployed inside corporate networks, and public internet scans of exposed Oracle T3 endpoints suggest only a small subset (likely in the low thousands) are directly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Internet Directory. Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Weakness
CWE-287, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.