Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw exists in the Oracle Unified Directory product of Oracle Fusion Middleware, specifically the OUD Core component, which permits an attacker to connect via LDAP without authentication and exploit the system. Successful exploitation results in full compromise of the Oracle Unified Directory, yielding complete confidentiality, integrity, and availability loss, and can affect other components due to a scope change. The weakness is reflected in a CVSS 3.1 vector with a base score of 10.0, illustrating an extremely severe vulnerability that is easily exploitable and requires no privileged access.

Affected Systems

Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0 are affected. No other products are listed as impacted, but the scope change indicates that additional Oracle Fusion Middleware components could be impacted if the directory is compromised.

Risk and Exploitability

The CVSS score of 10.0 indicates maximum severity, and the EPSS score of < 1% shows that exploitation is considered low probability at this time, though not impossible. The vulnerability is listed as not in CISA KEV, so no known widespread exploitation is documented yet. The likely attack vector is a remote LDAP connection from an unauthenticated attacker, allowing direct takeover of the directory service.

Generated by OpenCVE AI on August 4, 2026 at 04:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor‑issued patch or update to a fixed version as soon as it becomes available
  • Restrict external LDAP traffic to a limited set of trusted hosts using firewall or access control lists
  • Enable encrypted LDAP (LDAPS) or require client certificates to reduce the risk of unauthenticated access

Generated by OpenCVE AI on August 4, 2026 at 04:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Remote Takeover of Oracle Unified Directory

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Remote Takeover of Oracle Unified Directory

Sun, 26 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Remote LDAP Exploitation Enables Unauthenticated Takeover of Oracle Unified Directory
Weaknesses CWE-284
CWE-285

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Remote LDAP Exploitation Enables Unauthenticated Takeover of Oracle Unified Directory
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T18:29:01.416Z

Reserved: 2026-07-08T15:51:40.532Z

Link: CVE-2026-60360

cve-icon Vulnrichment

Updated: 2026-07-24T18:28:56.653Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function