Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Oracle Unified Directory core component of Oracle Fusion Middleware and is caused by improper privilege management, identified as CWE‑269. A low‑privileged attacker who can reach the LDAP interface over the network can exploit the flaw, achieving full compromise of the directory service. Successful exploitation results in loss of confidentiality, integrity, and availability because the attacker can read, modify, or delete directory entries and gain administrative control.

Affected Systems

Affected versions include Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0. These are components of Oracle Fusion Middleware, and the vulnerability pertains to the OUD Core component.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 reflects high severity, with significant confidentiality, integrity, and availability impact. The EPSS score is less than 1%, indicating a low likelihood of exploitation at present, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is via LDAP traffic from an external network and requires only low privileged credentials; no user interface is needed. If exploited, the attacker gains full control of the directory service.

Generated by OpenCVE AI on August 4, 2026 at 17:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Unified Directory update provided in the July 2026 CPU security alert
  • Restrict LDAP access to trusted networks or IP ranges using firewall rules
  • Enforce strict role‑based access control and enable strong authentication within Oracle Unified Directory
  • Continuously monitor LDAP logs for unusual activity and investigate anomalies

Generated by OpenCVE AI on August 4, 2026 at 17:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Low-privileged LDAP attack can compromise Oracle Unified Directory

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Low-privileged LDAP attack can compromise Oracle Unified Directory

Thu, 30 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege LDAP Exploit Enables Full Compromise of Oracle Unified Directory
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege LDAP Exploit Enables Full Compromise of Oracle Unified Directory
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T03:55:50.897Z

Reserved: 2026-07-08T15:51:40.536Z

Link: CVE-2026-60419

cve-icon Vulnrichment

Updated: 2026-07-24T15:56:56.783Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:30:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management