Description
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Full Compromise of Oracle Internet Directory via LDAP
Action: Immediate Patch
AI Analysis

Impact

The Oracle Internet Directory (OID) LDAP Server contains an access control flaw that allows an attacker with low-privilege credentials who can reach the LDAP service to fully compromise the directory. As the vulnerability’s CVSS vector indicates AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, it impacts confidentiality, integrity and availability. Attackers could bypass normal authorization checks and gain administrative control, potentially allowing takeover of the OID instance and, due to the scope change, affecting other components within the Oracle Fusion Middleware stack. The weakness aligns with CWE‑284: Improper Access Control.

Affected Systems

The affected product variants are Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0. These releases are part of Oracle Fusion Middleware and provide authentication and directory services across many enterprises. The advisory specifies only these two versions as vulnerable, and no other releases are mentioned.

Risk and Exploitability

The base CVSS score of 9.9 marks the vulnerability as critical, while the EPSS score of < 1% indicates the current exploitation probability is very low. The issue is not listed in the CISA KEV catalog. Although the description does not state the attack can occur without authentication, it is clear that an attacker must have network connectivity to the LDAP interface and possess at least low‑privilege credentials; this inference is based on the phrase “low privileged attacker with network access via LDAP.” If the LDAP service is reachable from the internet or from less trusted networks, the risk of initial compromise increases. Organizations should evaluate their LDAP exposure and apply the vendor’s fix promptly.

Generated by OpenCVE AI on September 20, 2026 at 10:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle security patch for Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0 as detailed in the Oracle advisory
  • Restrict LDAP access to trusted internal hosts or approved IP ranges using firewall or ACL rules
  • Configure the OID server to enforce strict LDAP authentication policies and enable logging of privileged operations
  • Monitor network traffic and OID logs for anomalous LDAP queries that could indicate exploitation attempts

Generated by OpenCVE AI on September 20, 2026 at 10:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Low Privilege LDAP Access Allows Full Compromise of Oracle Internet Directory

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title Low Privilege LDAP Access Allows Full Compromise of Oracle Internet Directory
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle internet Directory
CPEs cpe:2.3:a:oracle:internet_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:internet_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle internet Directory
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Internet Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:22:14.161Z

Reserved: 2026-08-31T15:40:57.336Z

Link: CVE-2026-83056

cve-icon Vulnrichment

Updated: 2026-09-17T14:59:25.487Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:14.230

Modified: 2026-09-17T16:17:50.020

Link: CVE-2026-83056

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T11:00:09Z

Weaknesses