Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The affected product, Oracle Unified Directory, contains a flaw that permits an unauthenticated attacker with network access via HTTP to gain read access to all data managed by the directory service. This flaw results from missing authentication checks, reflecting CWE-306 (Missing Authentication). The vulnerability is characterized by a CVSS 3.1 base score of 8.6, with the impact confined primarily to confidentiality while integrity and availability remain unchanged.

Affected Systems

Oracle Corporation’s Oracle Unified Directory is affected in the 12.2.1.4.0 and 14.1.2.1.0 releases. These versions are part of Oracle Fusion Middleware and are the only publicly documented affected builds.

Risk and Exploitability

The CVSS vector indicates that the attack is achievable over the network (AV:N), requires no prior authentication (PR:N) and needs no user interaction (UI:N). The EPSS score of less than 1% suggests a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalogue, but its high confidentiality impact and the fact that it does not require privileged access make it a notable risk for organizations exposing the directory over HTTP.

Generated by OpenCVE AI on August 2, 2026 at 22:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review the Oracle CPU July 2026 advisory to determine if a patch or hotfix is available and deploy it immediately on affected Oracle Unified Directory instances, as the patch addresses the missing authentication flaw (CWE-306).
  • If a patch is not yet available, isolate the directory service from the public network or restrict HTTP access to a limited set of trusted IP addresses using firewall or access control lists.
  • Ensure that the operating environment for Oracle Unified Directory enforces minimum necessary permissions and applies hardening guidelines recommended by Oracle to reduce overall exposure.

Generated by OpenCVE AI on August 2, 2026 at 22:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Full Data Read in Oracle Unified Directory

Thu, 30 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Grants Full Oracle Unified Directory Data Read
Weaknesses CWE-284

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Grants Full Oracle Unified Directory Data Read
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T19:14:23.231Z

Reserved: 2026-07-08T15:51:40.532Z

Link: CVE-2026-60359

cve-icon Vulnrichment

Updated: 2026-07-24T18:30:18.731Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:45:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function