Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Oracle Unified Directory OUD Core component allows an attacker with low privileges but network access via LDAP to bypass authentication controls and assume full control of the directory service. The vulnerability is exploitable over the network without any user interaction and can result in complete takeover of the Oracle Unified Directory service, affecting confidentiality, integrity, and availability, and represents an Access Control flaw (CWE-284).

Affected Systems

Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0, both part of Oracle Fusion Middleware, are affected. Deployments using these versions of the directory service are at risk, and attacks may also impact other Oracle products

Risk and Exploitability

The CVSS 3.1 base score of 9.9 indicates a Critical severity impact on all data and system operations. The EPSS score of less than 1% shows a low probability of exploitation at present, yet the exploit requires only network access to LDAP and a low‑privileged account, making it a realistic threat once discovered. The vulnerability is not yet listed in the CISA KEV catalog, so there are no confirmed active exploits known at the time of this analysis.

Generated by OpenCVE AI on August 4, 2026 at 03:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in the 2026.07 Security Update for Oracle Unified Directory to versions that address CVE-2026-60429.
  • Limit LDAP traffic to trusted internal networks and restrict access to authorized IP ranges only.
  • Enforce strong authentication by enabling LDAPS and disabling anonymous LDAP binds, ensuring all administrative operations require secure, authenticated sessions.

Generated by OpenCVE AI on August 4, 2026 at 03:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title LDAP Access Control Vulnerability in Oracle Unified Directory

Sun, 02 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Direct LDAP Access Vulnerability Enabling Full Control of Oracle Unified Directory

Thu, 30 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Direct LDAP Access Vulnerability Enabling Full Control of Oracle Unified Directory
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-30T03:55:32.457Z

Reserved: 2026-07-08T15:51:40.536Z

Link: CVE-2026-60429

cve-icon Vulnrichment

Updated: 2026-07-24T15:46:33.808Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:00:03Z

Weaknesses