CVE-2026-83066
moderateUnauthenticated Takeover of Oracle Internet Directory via T3/IIOP
CVE-2026-83066 is a critical (CVSS 9.8) vulnerability in the OID LDAP Server component of Oracle Internet Directory, part of Oracle Fusion Middleware, affecting versions 12.2.1.4.0 and 14.1.2.1.0. An unauthenticated remote attacker who can reach the server over the network via the T3 or IIOP protocols can exploit the flaw without any privileges or user interaction, and a successful attack can result in a complete takeover of the Oracle Internet Directory instance with high impact on confidentiality, integrity, and availability. Because OID often serves as a central LDAP/directory service, compromise could expose or allow manipulation of directory data and credentials relied on by downstream enterprise applications. Organizations running the affected OID versions with T3/IIOP listeners reachable by untrusted networks are at greatest risk. As of now, the flaw is not in the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept is known, so exploitation status is none known.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83066 to all Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0 deployments. Until patched, block or strictly limit T3 and IIOP access at the firewall and via WebLogic connection filters so only trusted administrator hosts can reach those protocols. Review directory server logs for unauthenticated T3/IIOP connection attempts and unexpected administrative changes as indicators of attempted compromise.
| Oracle Internet Directory (Fusion Middleware, OID LDAP Server component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Internet Directory. Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.