Junglewise Threat Intelligence

CVE-2026-83066: Oracle Internet Directory LDAP server remote takeover

CVE-2026-83066 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Technologies: Oracle Internet Directory. Vendors: Oracle.

Executive brief

Oracle Internet Directory is a directory service component of Oracle Fusion Middleware used to store and manage user and resource information across enterprise systems. This vulnerability allows an unauthenticated attacker on the network to gain complete control over the directory service without authentication, enabling them to read sensitive data, modify configurations, or disrupt directory operations that other applications depend on.

Technical details

This is a remote code execution or authentication bypass vulnerability in the OID LDAP Server component, accessible via the T3 and IIOP protocols. The vulnerability requires no authentication and can be exploited by an unauthenticated attacker with network access to the affected service. Successful exploitation results in complete takeover of the Oracle Internet Directory, allowing the attacker to compromise confidentiality, integrity, and availability of the directory service. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Internet Directory. Patch availability information is not provided in the advisory.

Affected products

  • Oracle Internet Directory 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-09-15: disclosed

References

Related threats