Vulnerability in Oracle Internet Directory Affects Oracle Fusion Middleware
CVE-2026-83058

9.9CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 September 2026

What is CVE-2026-83058?

A vulnerability exists in Oracle Internet Directory, part of Oracle Fusion Middleware, specifically affecting the OID LDAP Server component. Attackers with low privileges can exploit this vulnerability via network access to LDAP, potentially compromising the integrity and confidentiality of the Oracle Internet Directory. Given its foundational role, attacks could have broader implications for the security of related products. Successful exploitation may allow an attacker to gain unauthorized control, leading to significant disruptions and security breaches.

Affected Version(s)

Oracle Internet Directory 12.2.1.4.0

Oracle Internet Directory 14.1.2.1.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.