Oracle disclosed a critical vulnerability in the Oracle Internet Directory LDAP Server that lets a low-privileged network attacker take over the directory, and which Oracle says may significantly impact additional products beyond it.
What Is It
CVE-2026-83057 is a vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware, specifically the OID LDAP Server component. Oracle describes it as easily exploitable: an attacker with low privileges and network access via LDAP can compromise Oracle Internet Directory. Successful attacks result in takeover of Oracle Internet Directory.
The CVSS 3.1 base score is 9.9 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Attack complexity is low, no user interaction is required, and the impact to confidentiality, integrity, and availability is high across the board.
Why It Matters
The scope is marked as Changed. Oracle notes that while the vulnerability resides in Oracle Internet Directory, attacks may significantly impact additional products; the compromise is not necessarily contained to the vulnerable component. That scope change is what pushes the score from high to near-maximum.
Oracle Internet Directory is an LDAP directory service, so the assets at risk are the identity and authentication data the directory holds. The only barrier to exploitation is the low privilege requirement; everything else in the vector is wide open.
This CVE is not listed in the CISA Known Exploited Vulnerabilities catalog in the supplied data, and there is no confirmation of active exploitation in the wild.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Internet Directory (Oracle Fusion Middleware)
- Component: OID LDAP Server
- Affected supported versions: 12.2.1.4.0 and 14.1.2.1.0
Both affected versions are current supported releases, meaning the exposure covers actively deployed environments rather than only legacy installs.
Patch Status
Fusion Middleware fixes of this kind ship through Oracle's Critical Patch Update program, which releases on a fixed quarterly cadence in January, April, July, and October. The 2026-09-15 disclosure date carried in the supplied data falls outside that cadence and does not correspond to any published Critical Patch Update, so treat the date as unverified and confirm the fix against the CPU advisory that actually carries it; the most recent release (July 2026) or the next scheduled one (October 2026). Refer to that advisory for fixed version details and applicable patches. No specific CISA required action or remediation deadline is present in the supplied data, since the CVE does not appear in the KEV catalog.
The NVD record currently shows a vulnerability status of "Received," so the entry has not yet completed NVD analysis. Treat the Oracle advisory as the authoritative source for remediation guidance.
Sources
- Oracle Security Alerts; Critical Patch Update index: https://www.oracle.com/security-alerts/
- Oracle Critical Patch Update; July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-83057: https://nvd.nist.gov/vuln/detail/CVE-2026-83057