Description
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Full Compromise of Oracle Internet Directory via Unauthenticated LDAP Access
Action: Apply Patch
AI Analysis

Impact

The flaw resides in the Oracle Internet Directory LDAP Server and allows an unauthenticated attacker with network access to the LDAP port to bypass authentication and perform arbitrary operations. This results in total loss of confidentiality, integrity and availability of the directory service, effectively enabling a full takeover of Oracle Internet Directory. The vulnerability is indexed as CWE‑287 (Improper Authentication) and CWE‑306 (Missing Authentication for Critical Function).

Affected Systems

Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0 are affected. The problem exists in the OID LDAP Server component of Oracle Fusion Middleware and applies to all installations exposing this service.

Risk and Exploitability

The CVSS base score is 9.8, indicating a severe vulnerability with a high likelihood of successful exploitation. The EPSS score is less than 1% and the vulnerability is not yet listed in the CISA KEV catalog, suggesting that widespread exploitation is currently unlikely. However, the attack vector is purely network-based; any host that can reach the exposed LDAP endpoint can authenticate without credentials, execute arbitrary actions and achieve full control of the directory. The risk is high for systems that expose the LDAP service to untrusted networks and low for tightly isolated or firewall‑protected deployments.

Generated by OpenCVE AI on September 20, 2026 at 10:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Internet Directory patch supplied by Oracle that fixes the LDAP authentication flaw
  • Restrict access to the LDAP service to trusted networks or IP ranges using firewalls or host‑based ACLs
  • Enable LDAP over TLS (LDAPS) and disable plain LDAP wherever possible to enforce secure authentication

Generated by OpenCVE AI on September 20, 2026 at 10:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Access Leading to Full Compromise of Oracle Internet Directory

Thu, 17 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Access Leading to Full Compromise of Oracle Internet Directory

Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-306

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle internet Directory
CPEs cpe:2.3:a:oracle:internet_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:internet_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle internet Directory
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Internet Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T22:54:37.568Z

Reserved: 2026-08-31T15:40:57.335Z

Link: CVE-2026-83054

cve-icon Vulnrichment

Updated: 2026-09-15T22:45:46.796Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:14.000

Modified: 2026-09-22T19:08:35.797

Link: CVE-2026-83054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T10:45:18Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function