CTIPilot

Oracle Internet Directory (OID LDAP Server), unauthenticated flaw over LDAP, CVSS 10.0, September 2026 CSPU

cve · CVE-2026-83059

Coverage timeline
1
first 2026-09-20 → last 2026-09-20
Peak priority
high
1 high
Sources cited
2
2 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
8
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-20/oracle-september-2026-cspu-five-unauthenticated-cvss-10 · ATT&CK page ↗

Story timeline

  1. 2026-09-20Oracle's September 2026 Critical Security Patch Update carries six unauthenticated CVSS 10.0 flaws across WebLogic Server, Access Manager, Forms, Internet Directory, Platform Security for Java and Hyperion Financial Management
    trending-vulnerabilitiesSix CVSS 10.0 flaws needing no credential and no user interaction, in the middleware tier that fronts everything else

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • advisories.ncsc.nl1 (50%)
  • oracle.com1 (50%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Oracle Internet Directory (OID LDAP Server), unauthenticated flaw over LDAP, CVSS 10.0, September 2026 CSPU (1)

2026-09-20 · view entry permalink →

Oracle's September 2026 Critical Security Patch Update carries six unauthenticated CVSS 10.0 flaws across WebLogic Server, Access Manager, Forms, Internet Directory, Platform Security for Java and Hyperion Financial Management

Oracle published its September 2026 Critical Security Patch Update on 2026-09-15 (Rev 1, initial release) with 673 new security patches across its product families; Oracle Fusion Middleware alone accounts for 153 of them, and Oracle states that "78 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials" (Oracle, 2026-09-15). Six flaws in the release carry a CVSS 3.1 base score of 10.0 in Oracle's own risk matrix with Attack Vector Network, Attack Complexity Low, Privileges Required None, User Interaction None and Scope Changed, meaning an unauthenticated request across the network reaches high confidentiality and integrity impact and crosses a security boundary (the first five also reach high availability impact; Hyperion Financial Management's is rated none): CVE-2026-83021 in the Web Container of Oracle WebLogic Server over HTTP, CVE-2026-71133 in the Authentication Engine of Oracle Access Manager over HTTP, CVE-2026-83099 in Oracle Forms Services over HTTP, CVE-2026-83059 in the OID LDAP Server of Oracle Internet Directory over LDAP, CVE-2026-83020 in the centralized third-party jars of Oracle Platform Security for Java over HTTP, and CVE-2026-87230 in the Security component of Oracle Hyperion Financial Management over HTTP (Oracle, 2026-09-15). The Netherlands' national cyber-security centre relayed the Fusion Middleware half of the release as advisory NCSC-2026-0372 on 2026-09-16 and assigned it priority "Hoog", its high rating (NCSC-NL, 2026-09-16).

The Critical Security Patch Update is Oracle's second, higher-frequency release line, published alongside the quarterly cumulative Critical Patch Update rather than replacing it: Oracle describes it as providing "targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption" and says these updates "complement Oracle’s existing quarterly cumulative Critical Patch Updates (CPUs)" (Oracle, 2026-09-15). A patch calendar built only around the January, April, July and October quarterly dates therefore leaves the September release, and the four other off-quarter releases in the year, unscheduled.

Oracle discloses no exploitation technique, no proof-of-concept status and no in-the-wild activity for any of the six, which is its standing advisory practice; no source in this release names an exploited flaw. What forces the timeline is the shape of the flaws rather than an exploitation report. Each of the six is reachable by an unauthenticated network request against a component that exists to sit in front of other systems or to hold what they rely on: WebLogic's web container, Access Manager's authentication engine, an Internet Directory LDAP listener, Forms Services, the shared Java security jars underneath Fusion Middleware, and Hyperion Financial Management's own security component. Five of them are the single-sign-on, directory and application-server tiers that Swiss federal, cantonal and communal estates run legacy identity services on, and a Scope Changed rating on an authentication engine means the compromise does not stay inside the component that carries the flaw. The sixth sits elsewhere: Hyperion Financial Management is a financial-consolidation application from Oracle's separate Hyperion family, so it is the finance estate rather than the identity estate that needs checking for it.

Triage: exploitation of these components produces authentication and application-tier telemetry, not endpoint telemetry. On the identity tier, look for successful authorization decisions from Access Manager with no preceding credential-validation event, and for LDAP binds or searches against the OID listener from source ranges that no application integration uses. On the application tier, look for requests to WebLogic or Forms endpoints that return successfully without a prior session-establishment request in the same log sequence. Ordinary integrations and health checks produce the same request types, so the discriminator is the missing predecessor event, not the request itself.

This Critical Security Patch Update contains 153 new security patches for Oracle Fusion Middleware.

78 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.

A Critical Security Patch Update (CSPU) provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.

Oracle 2026-09-15

Builds on: 2026-08-20/oracle-august-2026-cpu-three-unauthenticated-cvss-10 · 2026-06-18/cve-2026-46978-cve-2026-35278-oracle-june-2026-cspu-unauthen

vulnerability20 Sep 13:38Zmulti-sourceOpen finding ↗
Sources: Oracle · NCSC-NL