CVE-2025-15579

Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection.  The vulnerability could lead to remote code execution, denial of service, or privilege escalation. This issue affects Directory Services: before 24.4.16, from 25.1 before 25.1.9, from 25.2 before 25.2.9, from 25.3 before 25.3.8, from 25.4 before 25.4.5, from 26.1 before 26.1.2.
CVSS

No CVSS.

Configurations

No configuration.

History

27 Feb 2026, 22:16

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de deserialización de datos no confiables en OpenText™ Directory Services permite la inyección de objetos. La vulnerabilidad podría conducir a ejecución remota de código, denegación de servicio o escalada de privilegios. Este problema afecta a Directory Services: desde la versión 10.5 hasta la 26.1.
Summary (en) Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection. The vulnerability could lead to remote code execution, denial of service, or privilege escalation. This issue affects Directory Services: from 10.5 through 26.1. (en) Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection.  The vulnerability could lead to remote code execution, denial of service, or privilege escalation. This issue affects Directory Services: before 24.4.16, from 25.1 before 25.1.9, from 25.2 before 25.2.9, from 25.3 before 25.3.8, from 25.4 before 25.4.5, from 26.1 before 26.1.2.

18 Feb 2026, 16:22

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-18 16:22

Updated : 2026-02-27 22:16


NVD link : CVE-2025-15579

Mitre link : CVE-2025-15579

CVE.ORG link : CVE-2025-15579


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data