Junglewise Threat Intelligence

CVE-2026-83054: Oracle Internet Directory LDAP authentication bypass

CVE-2026-83054 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Technologies: Oracle Internet Directory. Vendors: Oracle.

Executive brief

Oracle Internet Directory is a directory service component used by Oracle Fusion Middleware to manage user identities and access control. An unauthenticated remote attacker can exploit this vulnerability via the LDAP protocol to gain full administrative control over the directory service, compromising all stored user credentials, organizational data, and access privileges across dependent systems.

Technical details

This is an unauthenticated remote code execution or authentication bypass vulnerability in the OID LDAP Server component. The vulnerability requires only network access to the LDAP port and no user interaction or prior authentication; an attacker can exploit it directly from the network. Successful exploitation allows complete takeover of Oracle Internet Directory, including potential data exfiltration, modification, and denial of service. Patches are available from Oracle's September 2026 Critical Patch Update.

Affected products

  • Oracle Internet Directory 12.2.1.4.0 and 14.1.2.1.0

Timeline

  • 2026-09-15: disclosed: Published in Oracle Critical Patch Update

References

Related threats