Junglewise Threat Intelligence

CVE-2026-83062: Oracle Internet Directory LDAP authentication bypass

CVE-2026-83062 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Technologies: Oracle Internet Directory. Vendors: Oracle.

Executive brief

Oracle Internet Directory is a directory service used for managing user identities and access across enterprise applications. An unauthenticated network attacker can exploit this vulnerability to completely compromise the directory, potentially gaining control over user authentication and access controls for all connected systems.

Technical details

This is an authentication bypass vulnerability in Oracle Internet Directory's LDAP server component. An unauthenticated attacker with network-level access to the LDAP service can exploit the flaw without credentials or user interaction required. The vulnerability allows complete compromise of the directory service, resulting in full confidentiality, integrity, and availability impact. Affected versions are 12.2.1.4.0 and 14.1.2.1.0; patch availability should be verified through Oracle's security bulletins.

Affected products

  • Oracle Internet Directory 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-09-15: disclosed

References

Related threats