CVE-2025-15579

CRITICAL

OpenText Directory Services 10.5-26.1 - Deserialization

Title source: llm
STIX 2.1

Description

Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection.  The vulnerability could lead to remote code execution, denial of service, or privilege escalation. This issue affects Directory Services: before 24.4.16, from 25.1 before 25.1.9, from 25.2 before 25.2.9, from 25.3 before 25.3.8, from 25.4 before 25.4.5, from 26.1 before 26.1.2.

Scores

CVSS v4 9.5
EPSS 0.0049
EPSS Percentile 65.7%
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:Y/R:U/V:C/RE:M/U:Red

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-502
Status published
Products (6)
OpenText™/Directory Services < 24.4.16
OpenText™/Directory Services 25.1 - 25.1.9
OpenText™/Directory Services 25.2 - 25.2.9
OpenText™/Directory Services 25.3 - 25.3.8
OpenText™/Directory Services 25.4 - 25.4.5
OpenText™/Directory Services 26.1 - 26.1.2
Published Feb 18, 2026
Tracked Since Feb 18, 2026