Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). The supported version that is affected is 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Unified Directory accessible data as well as unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Unified Directory (OUD) Core suffers an easily exploitable vulnerability through LDAP that permits an attacker with low privilege and network access to create, delete, or modify data, thereby breaching confidentiality and integrity. Once breached, the attacker can gain unauthorized access to or alter critical data stored in the directory. The impact ranges from data manipulation to potential loss of critical information.

Affected Systems

Affected systems are Oracle Unified Directory version 14.1.2.1.0, part of Oracle Fusion Middleware. The vulnerability may also influence other products accessed through the directory due to the scope change noted in the advisory, increasing the risk to organizations that rely on OUD for authentication or access control.

Risk and Exploitability

The CVSS v3.1 score of 9.9 marks this as critical, with confidentiality, integrity, and availability damages. The EPSS score is below 1%, suggesting it is not widely exploited, and it is not listed in CISA’s KEV catalog. Nevertheless, the low attack complexity and requirement for low privilege coupled with network‑based LDAP access mean that a nearby attacker can easily exploit the flaw if LDAP services are reachable over the network. The risk profile remains high due to the severe potential data loss and unauthorized service disruption that could occur even with minimal privileges.

Generated by OpenCVE AI on August 4, 2026 at 03:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in the CPU July 2026 to address OUD 14.1.2.1.0
  • Restrict LDAP service access to only trusted hosts or VPN connections to reduce external exposure
  • Review and tighten LDAP role assignments and permissions, ensuring that low‑privilege users cannot perform creation or deletion operations

Generated by OpenCVE AI on August 4, 2026 at 03:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege LDAP Exploitation Enables Unauthorized Data Modification in Oracle Unified Directory

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege LDAP Exploitation Enables Unauthorized Data Modification in Oracle Unified Directory

Tue, 28 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title LDAP Access Abuse in Oracle Unified Directory Enabling Unauthorized Data Modification

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title LDAP Access Abuse in Oracle Unified Directory Enabling Unauthorized Data Modification
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). The supported version that is affected is 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Unified Directory accessible data as well as unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T03:55:53.471Z

Reserved: 2026-07-08T15:51:40.536Z

Link: CVE-2026-60422

cve-icon Vulnrichment

Updated: 2026-07-24T14:08:08.419Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:00:03Z

Weaknesses