Description
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

A flaw in Oracle Internet Directory’s LDAP server causes improper input validation, allowing a low‑privileged attacker with network access to send crafted LDAP requests that lead to a full takeover of the directory service. The compromise affects confidentiality, integrity, and availability of the directory, and could give the attacker extensive control over the service. Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0 are affected, as referenced in the Oracle Security Alert and listed in the CPE entries.

Affected Systems

Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0 are impacted. These versions are part of Oracle Fusion Middleware’s Identity Services.

Risk and Exploitability

The CVSS 3.1 base score of 9.9 marks the flaw as critical, while the EPSS score of < 1% indicates a very low current exploitation probability. The vulnerability is not in the CISA KEV catalog. Attackers need network reach to the LDAP port; the description does not state that authentication is required, so an attacker who can reach the directory service may exploit the flaw. The scope change noted in the description suggests that additional Oracle products could also be impacted.

Generated by OpenCVE AI on September 17, 2026 at 05:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Oracle Internet Directory security patch referenced in the Oracle.com/security-alerts/cspusep2026.html
  • If a patch cannot be applied immediately, restrict inbound LDAP traffic to trusted sources by configuring firewall or host‑based access controls, limiting access only to administrative IP ranges
  • Consider network segmentation or disabling LDAP services on externally exposed interfaces until the issue is resolved

Generated by OpenCVE AI on September 17, 2026 at 05:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title LDAP Input Validation Vulnerability Enables Remote Directory Takeover in Oracle Internet Directory
Weaknesses CWE-20

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle internet Directory
CPEs cpe:2.3:a:oracle:internet_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:internet_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle internet Directory
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Internet Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:22:20.997Z

Reserved: 2026-08-31T15:40:57.336Z

Link: CVE-2026-83055

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:14.113

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83055

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T06:00:09Z

Weaknesses
  • CWE-20

    Improper Input Validation