Junglewise Threat Intelligence

CVE-2026-83061: Oracle Internet Directory LDAP authentication bypass

CVE-2026-83061 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Technologies: Oracle Internet Directory. Vendors: Oracle.

Executive brief

Oracle Internet Directory is an LDAP-based directory service used to manage user identities and access control in enterprise environments. An unauthenticated attacker can remotely exploit this vulnerability via the network to completely compromise the directory server, potentially gaining unauthorized access to all identity and credential data stored within, disrupting authentication for dependent systems and applications.

Technical details

This vulnerability in the OID LDAP Server component allows unauthenticated attackers with network access to the LDAP port to bypass authentication controls and compromise the system. The vulnerability is easily exploitable (CVSS AV:N/AC:L/PR:N), requiring no user interaction or special preconditions. Successful exploitation results in complete system compromise with impacts across confidentiality, integrity, and availability—attackers can read sensitive directory data, modify identity information, and disrupt LDAP services. Oracle has released patches for affected versions 12.2.1.4.0 and 14.1.2.1.0 as part of their September 2026 security update.

Affected products

  • Oracle Internet Directory 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-09-15: disclosed

References

Related threats