Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an access control weakness allowing unauthenticated LDAP traffic to fully compromise Oracle Unified Directory. An attacker receives the ability to read, modify, or delete directory data, and can disrupt or shut down the service, resulting in total loss of confidentiality, integrity, and availability for the component.

Affected Systems

Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0, which are part of Oracle Fusion Middleware, are affected.

Risk and Exploitability

The CVSS v3.1 base score of 9.8 marks this flaw as critical; the EPSS score of < 1% indicates a low current exploitation probability, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is unauthenticated network access to the LDAP interface, which requires no credentials and therefore can be exploited by any host that can reach the directory server over the network.

Generated by OpenCVE AI on August 2, 2026 at 22:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s CPU July 2026 security patch for Unified Directory 12.2.1.4.0 and 14.1.2.1.0.
  • Restrict LDAP traffic to the directory servers with firewall rules or ACLs so that only trusted hosts can connect.
  • Disable the LDAP service on Unified Directory instances where it is not required for operation.

Generated by OpenCVE AI on August 2, 2026 at 22:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Access in Oracle Unified Directory Enables Full Takeover

Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Exploitation Enables Takeover of Oracle Unified Directory
Weaknesses CWE-284

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Exploitation Enables Takeover of Oracle Unified Directory
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T03:55:47.052Z

Reserved: 2026-07-08T15:51:40.532Z

Link: CVE-2026-60362

cve-icon Vulnrichment

Updated: 2026-07-24T17:06:35.679Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:45:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function