CVE-2025-15579
An Insecure Deserialization vulnerability has been discovered in OpenText™ Directory Services.
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection. The vulnerability could lead to remote code execution, denial of service, or privilege escalation. This issue affects Directory Services: before 24.4.16, from 25.1 before 25.1.9, from 25.2 before 25.2.9, from 25.3 before 25.3.8, from 25.4 before 25.4.5, from 26.1 before 26.1.2.
| CWE | CWE-502 |
| Vendor | opentext™ |
| Product | directory services |
| Published | Feb 18, 2026 |
| Last Updated | Feb 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for opentext™ directory services
Be the first to know when new unknown vulnerabilities affecting opentext™ directory services are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
OpenText™ / Directory Services
0 < 24.4.16 25.1 < 25.1.9 25.2 < 25.2.9 25.3 < 25.3.8 25.4 < 25.4.5 26.1 < 26.1.2
References
Credits
Dylan Pindur - Assetnote Adam Kues - Assetnote Tomais Williamson - Assetnote