Description
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Full Compromise of Oracle Internet Directory via Unauthenticated LDAP Access
Action: Apply Patch
AI Analysis

Impact

The flaw resides in the Oracle Internet Directory LDAP Server component and is rated CVSS 3.1 9.8, indicating total loss of confidentiality, integrity and availability. Attackers with network reach to an exposed LDAP endpoint can authenticate without credentials and execute arbitrary operations that grant complete control of the directory service. This ability to bootstrap authentication allows an attacker to manipulate directory entries and ultimately take over the directory service entirely.

Affected Systems

Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0 are affected. The vulnerability is specific to the OID LDAP Server within the Oracle Fusion Middleware stack.

Risk and Exploitability

Although the EPSS score is less than 1% and the vulnerability is not yet listed in CISA’s KEV catalog, the high CVSS base score and the description of “easily exploitable” indicate that an anonymous user who can reach the LDAP port on the target could readily use it. The attack vector is network-based; any host able to send LDAP traffic to the vulnerable service is a potential entry point. The risk is therefore high if the service is exposed to untrusted networks, but the probability of widespread exploitation remains low at the time of this analysis.

Generated by OpenCVE AI on September 17, 2026 at 04:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Oracle Internet Directory to the latest available patch that addresses the LDAP authentication flaw
  • Restrict LDAP port access using firewalls or ACLs so that only trusted infrastructure can reach the service
  • Disable or migrate to LDAPS (LDAP over TLS) so that authentication requires secure transport and stronger controls

Generated by OpenCVE AI on September 17, 2026 at 04:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Access Leading to Full Compromise of Oracle Internet Directory

Wed, 16 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-306

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle internet Directory
CPEs cpe:2.3:a:oracle:internet_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:internet_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle internet Directory
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Internet Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T22:54:37.568Z

Reserved: 2026-08-31T15:40:57.335Z

Link: CVE-2026-83054

cve-icon Vulnrichment

Updated: 2026-09-15T22:45:46.796Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:14.000

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T05:00:14Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function