🔐 CVE Alert

CVE-2025-15579

UNKNOWN 0.0

An Insecure Deserialization vulnerability has been discovered in OpenText™ Directory Services.

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection.  The vulnerability could lead to remote code execution, denial of service, or privilege escalation. This issue affects Directory Services: before 24.4.16, from 25.1 before 25.1.9, from 25.2 before 25.2.9, from 25.3 before 25.3.8, from 25.4 before 25.4.5, from 26.1 before 26.1.2.

CWE CWE-502
Vendor opentext™
Product directory services
Published Feb 18, 2026
Last Updated Feb 27, 2026
Stay Ahead of the Next One

Get instant alerts for opentext™ directory services

Be the first to know when new unknown vulnerabilities affecting opentext™ directory services are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

OpenText™ / Directory Services
0 < 24.4.16 25.1 < 25.1.9 25.2 < 25.2.9 25.3 < 25.3.8 25.4 < 25.4.5 26.1 < 26.1.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
support.opentext.com: https://support.opentext.com/csm?id=ot_kb_unauthenticated&sysparm_article=KB0859600&sys_kb_id=f82c01214707b6144549b6bd416d43b7&spa=1

Credits

Dylan Pindur - Assetnote Adam Kues - Assetnote Tomais Williamson - Assetnote