Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Unified Directory allows a low‑privileged attacker with LDAP network access to compromise the directory server. Because the flaw gives the attacker control over the LDAP service, the attacker can gain full confidentiality, integrity, and availability of the directory. The weakness represents an improper access control that permits takeover of the Oracle Unified Directory instance, effectively resulting in full directory takeover and system compromise.

Affected Systems

Oracle Corporation’s Oracle Unified Directory component of Oracle Fusion Middleware is affected. Versions 12.2.1.4.0 and 14.1.2.1.0 are explicitly listed as vulnerable applications.

Risk and Exploitability

The CVSS v3.1 base score of 9.9 illustrates the extreme severity, and the EPSS score of less than 1 percent indicates a low probability of exploitation at present, yet the vulnerability is classified as easily exploitable with a network attack vector (LDAP). The flaw also changes scope, meaning that successful compromise may impact related components. Though not currently listed in CISA’s KEV catalog, the combination of high impact and low exploitation probability necessitates immediate attention. An attacker with limited local privileges can leverage the LDAP interface to elevate authority and eventually take over the entire directory service.

Generated by OpenCVE AI on August 4, 2026 at 04:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch or upgrade provided in the Oracle Security Alert CPU July 2026 for Oracle Unified Directory.
  • Restrict LDAP network access to trusted hosts or implement firewall rules limiting inbound LDAP connections to authorized IP ranges.
  • Implement strict access controls and audit policies on the LDAP server to limit use of privileged commands and monitor for anomalous activity.

Generated by OpenCVE AI on August 4, 2026 at 04:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title High‑Severity LDAP Directory Takeover Vulnerability in Oracle Unified Directory

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title High‑Severity LDAP Directory Takeover Vulnerability in Oracle Unified Directory

Mon, 27 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege LDAP Exploit Enables Full Compromise of Oracle Unified Directory
Weaknesses CWE-269
CWE-284

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege LDAP Exploit Enables Full Compromise of Oracle Unified Directory
Weaknesses CWE-269
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T03:55:45.494Z

Reserved: 2026-07-08T15:51:40.532Z

Link: CVE-2026-60361

cve-icon Vulnrichment

Updated: 2026-07-24T18:27:16.838Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function