Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Unified Directory accessible data as well as unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A weakness in the Oracle Unified Directory OUD Core component permits a low‑privileged attacker that can reach the directory service via LDAP to create, delete, or modify critical entries. The flaw results in significant confidentiality and integrity loss, and because OUD is often used by downstream Oracle applications, the impact can propagate to those products. The vulnerability does not enable arbitrary code execution but grants the attacker full write access to directory data, effectively allowing the attacker to alter authentication information, group memberships, and other sensitive attributes.

Affected Systems

Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0 are the only versions currently marked as affected. No other product versions or components have been listed as impacted.

Risk and Exploitability

The CVSS 3.1 Base Score of 8.2 signals a high severity with substantial confidentiality and integrity impact. The EPSS score of less than 1% indicates a low probability of exploitation at this time, and the vulnerability is not catalogued in the CISA KEV list. Exploitation requires network access to the LDAP interface and a low‑privileged account that can send crafted LDAP modify requests; upon success the attacker acquires comprehensive write authority over the directory and can thereby corrupt or expose data accessed by other Oracle products.

Generated by OpenCVE AI on August 4, 2026 at 03:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle's security patch for Unified Directory 12.2.1.4.0 and 14.1.2.1.0 to fix the access‑control weakness.
  • Restrict LDAP service access to trusted hosts and enforce network segmentation so only authorized systems can contact the directory.
  • Implement least‑privilege ACLs for LDAP users, allowing modify operations only for accounts that truly require them.
  • Enable auditing of LDAP modify operations and regularly review logs for suspicious activity.

Generated by OpenCVE AI on August 4, 2026 at 03:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Privilege Abuse in Oracle Unified Directory Allowing Unauthorized Data Modification

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Privilege Abuse in Oracle Unified Directory Allowing Unauthorized Data Modification

Tue, 28 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthorized LDAP Operations Expose Oracle Unified Directory Data

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthorized LDAP Operations Expose Oracle Unified Directory Data
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Unified Directory accessible data as well as unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T03:55:51.942Z

Reserved: 2026-07-08T15:51:40.536Z

Link: CVE-2026-60421

cve-icon Vulnrichment

Updated: 2026-07-24T14:04:59.836Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:00:03Z

Weaknesses