Unauthorized Access Vulnerability in Oracle Internet Directory by Oracle
CVE-2026-61241
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 18 August 2026
Badges
What is CVE-2026-61241?
An exploitable vulnerability exists in the Oracle Internet Directory component of Oracle Fusion Middleware. This issue permits an unauthenticated attacker with network access via LDAP to potentially compromise the Oracle Internet Directory, enabling them to take control over the system. Notably, while the vulnerability resides within the Oracle Internet Directory, its exploitation may result in significant impacts on other related products, thereby broadening the scope of possible consequences. The affected versions are 12.2.1.4.0 and 14.1.2.1.0.
Affected Version(s)
Oracle Internet Directory 12.2.1.4.0
Oracle Internet Directory 14.1.2.1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.