Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker with network connectivity to the LDAP service can take full control of the directory server without any authentication. The vulnerability is significant, as it can lead to complete compromise impacting confidentiality, integrity, and availability of the data stored by the directory. The CVSS 3.1 base score of 8.1 indicates that the vulnerability is severe and carries high potential for damage.

Affected Systems

Affected systems are the Oracle Unified Directory component of Oracle Fusion Middleware in the 12.2.1.4.0 and 14.1.2.1.0 releases. These versions are referenced by the CPE strings provided and correspond to the standard product naming structure used by Oracle.

Risk and Exploitability

The risk of exploitation is moderated by the low EPSS score of less than 1%, and the vulnerability has not been reported in the CISA KEV catalog. Nonetheless, the attack vector is straightforward: an unauthenticated network attacker can send a crafted LDAP request to the directory server and gain administrative control. No special privileges or credentials are required, which makes broad exploitation plausible in environments with permissive LDAP access.

Generated by OpenCVE AI on August 5, 2026 at 02:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Unified Directory update released in CPU-2026-07, which addresses the missing authentication flaw identified as CWE‑306.
  • If the patch cannot be applied immediately, restrict LDAP network access to trusted hosts or firewall the LDAP ports (389/636) from external networks.
  • Enable detailed logging of LDAP bind operations and monitor logs for anomalous bind attempts to detect potential exploitation.

Generated by OpenCVE AI on August 5, 2026 at 02:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Takeover in Oracle Unified Directory

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Takeover in Oracle Unified Directory

Thu, 30 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Access Exploitable for Oracle Unified Directory Takeover
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Access Exploitable for Oracle Unified Directory Takeover
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T03:55:48.571Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60417

cve-icon Vulnrichment

Updated: 2026-07-24T16:02:17.415Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function