Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a privilege escalation flaw in Oracle Unified Directory that lets an attacker with high‑privilege LDAP credentials take full control of the directory service. This weakness is a CWE‑269 elevation of privilege error, and it results in complete compromise of confidentiality, integrity, and availability of the directory, potentially allowing further attacks on connected applications. Based on the description, it is inferred that the attacker exploits the LDAP protocol by performing privileged bind requests and then using those rights to modify or delete directory entries, effectively hijacking the system.

Affected Systems

Oracle Unified Directory in Oracle Fusion Middleware is affected. The specific releases impacted are version 12.2.1.4.0 and 14.1.2.1.0. No other vendors or product lines are listed in the advisory.

Risk and Exploitability

The CVSS 3.1 score of 7.2 indicates high severity, with serious confidentiality, integrity, and availability impacts. The EPSS score is less than 1%, implying a low probability of exploitation at present, and the vulnerability is not listed in CISA KEV. The likely attack vector is the LDAP network interface, and the exploitation requires an attacker to already possess or acquire high‑privilege LDAP credentials within the environment, limiting the threat scope to systems with such credentials exposed over the network.

Generated by OpenCVE AI on August 4, 2026 at 17:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Unified Directory patch that is part of the Oracle Critical Patch Update for versions 12.2.1.4.0 and 14.1.2.1.0 as announced in the July 2026 security alert.
  • Limit high‑privilege LDAP accounts to only those required for operation and remove or disable any nonessential privileged accounts.
  • Segment LDAP traffic so that only a narrow set of trusted hosts can communicate with the Oracle Unified Directory server, using firewall rules or network segmentation.
  • Enable detailed LDAP audit logging, monitor for unusual bind or modify requests, and investigate suspicious activity promptly.

Generated by OpenCVE AI on August 4, 2026 at 17:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title LDAP Privilege Escalation Leading to Oracle Unified Directory Takeover

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title LDAP Privilege Escalation Leading to Oracle Unified Directory Takeover

Thu, 30 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title LDAP Privilege Escalation in Oracle Unified Directory
Weaknesses CWE-284
CWE-285

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title LDAP Privilege Escalation in Oracle Unified Directory
Weaknesses CWE-284
CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T03:55:50.090Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60418

cve-icon Vulnrichment

Updated: 2026-07-24T15:59:34.169Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:30:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management