CVE-2025-15579
CRITICALOpenText Directory Services 10.5-26.1 - Deserialization
Title source: llmDescription
Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection. The vulnerability could lead to remote code execution, denial of service, or privilege escalation. This issue affects Directory Services: before 24.4.16, from 25.1 before 25.1.9, from 25.2 before 25.2.9, from 25.3 before 25.3.8, from 25.4 before 25.4.5, from 26.1 before 26.1.2.
Scores
CVSS v4
9.5
EPSS
0.0049
EPSS Percentile
65.7%
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:Y/R:U/V:C/RE:M/U:Red
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-502
Status
published
Products (6)
OpenText™/Directory Services
< 24.4.16
OpenText™/Directory Services
25.1 - 25.1.9
OpenText™/Directory Services
25.2 - 25.2.9
OpenText™/Directory Services
25.3 - 25.3.8
OpenText™/Directory Services
25.4 - 25.4.5
OpenText™/Directory Services
26.1 - 26.1.2
Published
Feb 18, 2026
Tracked Since
Feb 18, 2026