Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data as well as unauthorized update, insert or delete access to some of Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-07-21
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Unified Directory product contains a flaw that permits an attacker with low privileges and network access over LDAP to read or modify directory data. This weakness allows the adversary to enumerate and retrieve sensitive attributes, and in some cases to alter or delete entries. The impact is primarily confidentiality, with the possibility of altering integrity for a subset of data, as reflected in the CVSS vector.

Affected Systems

The flaw affects Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0, which are part of Oracle Fusion Middleware. The issue may also extend to other Oracle products that rely on the directory service, thereby broadening the potential scope.

Risk and Exploitability

The CVSS score of 8.5 denotes a high severity, and the EPSS score of less than 1% indicates low current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog, implying no known live attacks. Attackers can exploit the flaw over the network via LDAP with only low privileges, potentially compromising all accessible directory data. Given these factors, the risk remains significant for organizations dependent on Oracle Unified Directory.

Generated by OpenCVE AI on August 2, 2026 at 22:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or upgrade Oracle Unified Directory to a non‑affected version.
  • Restrict LDAP access to trusted hosts and network segments to limit exposure for low‑privileged attackers.
  • Review and enforce minimal privilege configurations for all user accounts that interact with the directory service.

Generated by OpenCVE AI on August 2, 2026 at 22:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege LDAP Access Enables Unauthorized Data Access in Oracle Unified Directory

Thu, 30 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege LDAP Access Enables Unauthorized Data Access in Oracle Unified Directory

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title LDAP-Based Unauthorized Access Vulnerability in Oracle Unified Directory
Weaknesses CWE-269
CWE-285

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title LDAP-Based Unauthorized Access Vulnerability in Oracle Unified Directory
Weaknesses CWE-269
CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data as well as unauthorized update, insert or delete access to some of Oracle Unified Directory accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:34:27.529Z

Reserved: 2026-07-08T15:51:40.536Z

Link: CVE-2026-60426

cve-icon Vulnrichment

Updated: 2026-07-24T15:34:16.443Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:30:04Z

Weaknesses