Description
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Full Compromise of Oracle Internet Directory via LDAP
Action: Immediate Patch
AI Analysis

Impact

The Oracle Internet Directory (OID) LDAP Server contains an easily exploitable flaw that permits an attacker with only low‑privilege credentials and network connectivity to LDAP traffic to fully compromise the directory service. The vulnerability enables the attacker to bypass normal access controls and assume administrative control, resulting in complete confidentiality, integrity and availability compromise of the OID instance. The flaw is characterized by the CVSS vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H and carries a 9.9 base score. This flaw aligns with CWE-284: Improper Access Control.

Affected Systems

Affected Oracle products are Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0. These releases are part of Oracle Fusion Middleware and are used for authentication and directory services in many enterprise environments. The advisory lists both versions as vulnerable; no other versions are affected according to the current data.

Risk and Exploitability

The CVSS 9.9 score reflects high severity, and the EPSS value indicates that the exploit probability is very low at present; however, the vulnerability can be leveraged remotely over LDAP without authentication, and the scope change makes it possible to affect other components. The advisory does not list this issue in the CISA KEV catalog, but the lack of exploitation data does not reduce the risk, especially for organizations that expose LDAP services externally. Attackers can achieve full system ingress by simply sending crafted LDAP requests over the network, and the low privilege requirement lowers the bar for initial compromise.

Generated by OpenCVE AI on September 17, 2026 at 04:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch for Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0 as detailed in the Oracle advisory
  • Restrict LDAP access to trusted internal hosts or approved IP ranges using firewall or ACL rules
  • Configure the OID server to enforce strict LDAP authentication policies and enable logging of privileged operations
  • Monitor network traffic and OID logs for anomalous LDAP queries that could indicate exploitation attempts

Generated by OpenCVE AI on September 17, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title Low Privilege LDAP Access Allows Full Compromise of Oracle Internet Directory
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle internet Directory
CPEs cpe:2.3:a:oracle:internet_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:internet_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle internet Directory
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Internet Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T20:03:08.190Z

Reserved: 2026-08-31T15:40:57.336Z

Link: CVE-2026-83056

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:14.230

Modified: 2026-09-16T19:36:43.087

Link: CVE-2026-83056

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T04:30:08Z

Weaknesses