Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in Oracle Unified Directory that allows an unauthenticated attacker with network access via LDAP to compromise the system. The flaw, while difficult to exploit, grants full takeover of the Oracle Unified Directory service. The CVSS base score is 9.0, indicating significant confidentiality, integrity, and availability impacts.

Affected Systems

Oracle Unified Directory, part of Oracle Fusion Middleware, is affected in versions 12.2.1.4.0 and 14.1.2.1.0. Because the vulnerability can change the scope of the compromise, additional Oracle products that rely on the directory could also be impacted.

Risk and Exploitability

The exploit requires network access to the LDAP interface and no authentication, yet it has a high complexity requirement. EPSS indicates a very low current probability of exploitation, but the lack of a KEV listing does not mitigate the potential for a future, high‑impact attack. The high CVSS score combined with scope change suggests a severe risk if the flaw is exploited.

Generated by OpenCVE AI on August 2, 2026 at 22:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Unified Directory patch or upgrade to a version where the flaw is fixed
  • Limit LDAP network exposure by restricting access to trusted networks or applying firewall rules
  • Enable auditing and monitor LDAP logs for unauthorized access attempts

Generated by OpenCVE AI on August 2, 2026 at 22:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Exploit Enables Complete Takeover of Oracle Unified Directory

Tue, 28 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Exploit Compromises Oracle Unified Directory
Weaknesses CWE-287

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated LDAP Exploit Compromises Oracle Unified Directory
Weaknesses CWE-287

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T03:55:55.020Z

Reserved: 2026-07-08T15:51:40.536Z

Link: CVE-2026-60424

cve-icon Vulnrichment

Updated: 2026-07-24T15:35:36.112Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:30:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function