Junglewise Threat Intelligence

CVE-2026-83057: Oracle Internet Directory LDAP server privilege escalation

CVE-2026-83057 · Severity: critical · CVSS 9.9 · Published 2026-09-15

Technologies: Oracle Internet Directory. Vendors: Oracle.

Executive brief

Oracle Internet Directory is a directory service used to manage identities and authentication across Oracle Fusion Middleware environments. A low-privileged attacker with network access can exploit a flaw in the LDAP server component to gain complete administrative control over the directory, potentially compromising all systems relying on it for identity management and authentication.

Technical details

A network-exploitable vulnerability in the OID LDAP Server component allows a low-privileged attacker with LDAP network access to escalate privileges and achieve full system compromise. The vulnerability requires the attacker to already have network connectivity to the LDAP service, but no high-level privileges are needed to trigger the exploit. Successful exploitation results in complete takeover of Oracle Internet Directory, with additional scope impact affecting dependent systems that rely on it for authentication and authorization. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. A patch is expected through Oracle's security updates.

Affected products

  • Oracle Internet Directory 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: advisory

References

Related threats