Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows a low‑privileged attacker with network access to the LDAP service of Oracle Unified Directory to compromise the entire directory service, leading to a full takeover. The flaw is easily exploitable and results in complete loss of confidentiality, integrity, and availability for the affected system.

Affected Systems

Oracle Corporation’s Oracle Unified Directory product, specifically versions 12.2.1.4.0 and 14.1.2.1.0.

Risk and Exploitability

The CVSS base score of 8.8 highlights severe impact on confidentiality, integrity, and availability. The EPSS score of less than 1% indicates a low probability of public exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need only low privilege and network access via LDAP, with no user interaction required. Once exploited, the attacker can take full control of the Oracle Unified Directory instance.

Generated by OpenCVE AI on August 4, 2026 at 03:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch for Oracle Unified Directory or upgrade to a non‑vulnerable version.
  • Restrict LDAP traffic to trusted internal hosts or apply firewall rules to limit external access.
  • Enforce strict authentication and authorization controls on the LDAP service, ensuring only privileged accounts have directory modification rights.
  • Monitor LDAP logs for suspicious activity and react to anomalies promptly.

Generated by OpenCVE AI on August 4, 2026 at 03:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title LDAP Exploit Enables Full Takeover of Oracle Unified Directory

Sun, 02 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title LDAP Privilege Escalation Leading to Full Oracle Unified Directory Compromise
Weaknesses CWE-269
CWE-285

Thu, 30 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title LDAP Privilege Escalation Leading to Full Oracle Unified Directory Compromise
Weaknesses CWE-269
CWE-285

Thu, 30 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title LDAP‑Based Privilege Escalation Leading to Oracle Unified Directory Compromise
Weaknesses CWE-264
CWE-285

Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title LDAP‑Based Privilege Escalation Leading to Oracle Unified Directory Compromise
Weaknesses CWE-264
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-30T03:55:33.208Z

Reserved: 2026-07-08T15:51:40.536Z

Link: CVE-2026-60430

cve-icon Vulnrichment

Updated: 2026-07-24T15:45:46.092Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:00:03Z

Weaknesses