Vulnerability in Oracle Internet Directory Affects Oracle Fusion Middleware
CVE-2026-83057

9.9CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-83057?

CVE-2026-83057 is a critical vulnerability found in the Oracle Internet Directory component of Oracle Fusion Middleware. Specifically affecting versions 12.2.1.4.0 and 14.1.2.1.0, this vulnerability allows a low-privileged attacker with network access via LDAP to take control of the Oracle Internet Directory. The nature of the flaw makes it easily exploitable, which raises significant security concerns for organizations utilizing affected versions of the software. Should an attacker successfully exploit this vulnerability, they can achieve complete takeover of the Oracle Internet Directory, compromising the confidentiality, integrity, and availability of data stored and processed by the system. The vulnerability is rated with a high CVSS score of 9.9, indicating its severe potential impact on organizational security.

Potential impact of CVE-2026-83057

  1. Unauthorized System Access: Successful exploitation can grant attackers full control of the Oracle Internet Directory, leading to unauthorized access to sensitive organizational data and potential misuse of permissions, effectively bypassing existing security measures.

  2. Data Breaches: The compromise of confidentiality and integrity can expose sensitive information, leading to extensive data breaches. Such breaches may have regulatory consequences and damage an organization's reputation.

  3. Widespread Product Vulnerability: Since the Oracle Internet Directory interacts with other systems and applications, successful attacks could propagate threats beyond the immediate component, potentially impacting various enterprise functionalities and increasing the scope of an attack across an organization’s infrastructure.

Affected Version(s)

Oracle Internet Directory 12.2.1.4.0

Oracle Internet Directory 14.1.2.1.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.