Junglewise Threat Intelligence

CVE-2026-83058: Oracle Internet Directory LDAP server privilege escalation

CVE-2026-83058 · Severity: critical · CVSS 9.9 · Published 2026-09-15

Technologies: Oracle Internet Directory. Vendors: Oracle.

Executive brief

Oracle Internet Directory is a directory service component of Oracle Fusion Middleware used for user and identity management across enterprise systems. A low-privileged attacker with network access to the LDAP service can exploit this vulnerability to take complete control of the directory system, affecting confidentiality, integrity, and availability of all dependent applications and services.

Technical details

This is a privilege escalation vulnerability in the OID (Oracle Internet Directory) LDAP Server component. The vulnerability is easily exploitable and requires only low-privileged network access via LDAP (no complex configuration needed). An authenticated attacker can achieve complete system compromise including full confidentiality, integrity, and availability impact. The scope is changed, meaning successful exploitation can impact other Oracle Fusion Middleware products that depend on this directory service. Patches are expected to be available through Oracle's critical patch updates.

Affected products

  • Oracle Internet Directory 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-09-15: disclosed

References

Related threats