Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-06-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker able to connect to the LDAP service of Oracle Unified Directory can fully compromise the directory database, gaining control of credentials, configuration, and management functions. The flaw allows the attacker to read and modify all confidential data, tamper with system integrity, and disrupt service availability, resulting in a total loss of confidentiality, integrity, and availability as reflected by the CVSS 3.1 Base Score of 9.8. The vulnerability is caused by improper authentication handling within the LDAP component, enabling an attacker to perform privileged actions without credentials.

Affected Systems

Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0 are affected. These versions are part of Oracle Fusion Middleware and provide directory services accessed over the network via LDAP. Any deployment of the specified products that is exposed to external or untrusted networks is at risk.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical risk, and the EPSS score of less than 1% suggests that, although the flaw is easily exploitable, it is presently unlikely to be widely used in the wild. The vulnerability is accessible over the standard LDAP ports without authentication, so a network attacker with visibility of those ports can freely exploit the issue. Because the flaw is not listed in the CISA KEV catalog, no widespread exploit campaigns have been confirmed, but the potential damage warrants immediate action.

Generated by OpenCVE AI on June 17, 2026 at 20:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s security portal for the latest patch or upgrade to a fixed release of Oracle Unified Directory and apply it immediately
  • Restrict LDAP traffic to trusted networks or VLANs and enforce strict firewall rules to limit exposure
  • If patching cannot be performed immediately, disable external LDAP access and require authentication for all directory services until a fix is applied

Generated by OpenCVE AI on June 17, 2026 at 20:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T15:34:20.253Z

Reserved: 2026-05-18T15:55:10.296Z

Link: CVE-2026-46773

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T22:30:05Z

Weaknesses

No weakness.