LDAP Server Vulnerability in Oracle Internet Directory Product by Oracle
CVE-2026-61248

9.9CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-61248?

A security vulnerability has been identified in Oracle Internet Directory's LDAP Server component, potentially allowing low-privileged attackers with network access to exploit this flaw. A successful attack could lead to unauthorized control over the Oracle Internet Directory, severely impacting the confidentiality, integrity, and availability of the affected system. This issue arises from inadequate security measures within the server, enabling a shift in the attack's scope and posing risks to additional interconnected products.

Affected Version(s)

Oracle Internet Directory 12.2.1.4.0

Oracle Internet Directory 14.1.2.1.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.