CVE-2025-15579: Opentext Directory Services
Critical severity, CVSS 9.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection. The vulnerability could lead to remote code execution, denial of service, or privilege escalation. This issue affects Directory Services: before 24.4.16, from 25.1 before 25.1.9, from 25.2 before 25.2.9, from 25.3 before 25.3.8, from 25.4 before 25.4.5, from 26.1 before 26.1.2.
Affected products
- Opentext Directory Services: before 24.4.16 (fixed in 24.4.16); from 25.1, before 25.1.9 (fixed in 25.1.9); from 25.2, before 25.2.9 (fixed in 25.2.9); from 25.3, before 25.3.8 (fixed in 25.3.8); from 25.4, before 25.4.5 (fixed in 25.4.5); from 26.1, before 26.1.2 (fixed in 26.1.2)
Published 2026-02-18. Last modified 2026-06-17.