A critical security vulnerability (CVE-2026-61241) has been disclosed in Oracle Internet Directory, part of Oracle Fusion Middleware. The flaw exists in the OID LDAP Server component, affecting versions 12.2.1.4.0 and 14.1.2.1.0. This vulnerability allows unauthenticated attackers with network access to exploit the LDAP interface and achieve full system takeover. The CVSS 3.1 score of 10.0 reflects its ease of exploitation and severe impact, including potential scope expansion to compromise additional systems. Attackers could exfiltrate sensitive data, modify configurations, or disrupt operations. Organizations running affected versions are strongly advised to apply vendor-provided patches immediately. Until patched, network-level mitigations such as restricting LDAP access to trusted sources are recommended. This vulnerability underscores the importance of timely updates for enterprise directory services, as exploitation could lead to widespread infrastructure compromise.
CRITICAL
CVSS 10.0
CVE-2026-61241
2026-08-19
Critical LDAP Server Vulnerability in Oracle Internet Directory (CVE-2026-61241)
A critical vulnerability in Oracle Internet Directory's LDAP server allows unauthenticated remote attackers to take control. Affects versions 12.2.1.4.0 and 14.1.2.1.0. Immediate patching required due to high exploitability and severe impact.