PT-2026-77497 · Oracle · Oracle Internet Directory

CVE-2026-61241

·

Published

2026-08-18

·

Updated

2026-08-27

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0
Description An issue exists in the OID LDAP Server component of Oracle Fusion Middleware due to insecure privilege management. An unauthenticated attacker with network access via the LDAP protocol can exploit this to compromise the Oracle Internet Directory, potentially resulting in a full system takeover. This may also significantly impact other integrated products through a scope change.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Improper Privilege Management

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12004
CVE-2026-61241

Affected Products

Oracle Internet Directory