Junglewise Threat Intelligence

CVE-2026-83056: Oracle Internet Directory LDAP privilege escalation

CVE-2026-83056 · Severity: critical · CVSS 9.9 · Published 2026-09-15

Technologies: Oracle Internet Directory. Vendors: Oracle.

Executive brief

Oracle Internet Directory (OID) is a directory service component used in Oracle Fusion Middleware to manage user identities and access control. A privilege escalation vulnerability in the OID LDAP server allows a low-privileged network attacker to gain complete control over the directory service and potentially impact other connected systems. Successful exploitation could result in complete compromise of user authentication, authorization data, and downstream systems that depend on the directory.

Technical details

The vulnerability exists in the OID LDAP Server component and is easily exploitable by a low-privileged attacker with network access via LDAP protocol. The attack requires minimal preconditions (low privilege account, network reachability) and does not require user interaction. Successful exploitation results in complete takeover (confidentiality, integrity, and availability impact) of Oracle Internet Directory with scope change, meaning the impact extends beyond the vulnerable component to additional Oracle products that rely on the directory service. The vulnerability affects OID versions 12.2.1.4.0 and 14.1.2.1.0.

Affected products

  • Oracle Internet Directory 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-09-15: disclosed

References

Related threats