Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the Oracle Unified Directory component of Oracle Fusion Middleware, allowing an attacker who already possesses high‑privilege credentials and can reach the system via LDAP to take full control of the directory service. The vulnerability can be exploited easily and results in loss of confidentiality, integrity and availability of the directory, potentially affecting any applications that rely on it. The weakness is reflected in the identified CWEs, which indicate improper and missing authorization checks.

Affected Systems

Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0 are listed as affected. These releases have been confirmed to contain the vulnerability and have been documented as vulnerable in Oracle’s security advisories.

Risk and Exploitability

The CVSS v3.1 base score of 7.2 denotes a high‑impact issue, yet the EPSS score is reported as less than 1 %, indicating a low current exploitation probability. The vulnerability is not included in the CISA KEV catalog. The attacker must be able to reach the LDAP service and possess high‑privilege credentials within the target network; no public remote launch method is described. Based on typical enterprise environments, internal LDAP traffic is commonly available, which could lend the vulnerability an additional feasible attack vector for insiders. However, this statement is inferred from general network practices and is not explicitly stated in the vendor’s description.

Generated by OpenCVE AI on August 4, 2026 at 17:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the most recent Oracle Unified Directory patch or upgrade to a version that addresses CVE-2026-60519.
  • If a patch or upgrade cannot be applied immediately, isolate the directory service by restricting LDAP traffic to a trusted internal segment and enforce strict network segmentation.
  • Enforce the principle of least privilege for accounts that have LDAP write access, and implement monitoring and auditing of LDAP operations to detect anomalous activity.

Generated by OpenCVE AI on August 4, 2026 at 17:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title High-Privilege LDAP Exploit Allows Complete Compromise of Oracle Unified Directory

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title High-Privilege LDAP Exploit Allows Complete Compromise of Oracle Unified Directory

Thu, 30 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Oracle Unified Directory LDAP Attack Allows Full Compromise
Weaknesses CWE-285
CWE-862

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Oracle Unified Directory LDAP Attack Allows Full Compromise
Weaknesses CWE-285
CWE-862

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-30T03:55:33.955Z

Reserved: 2026-07-08T15:51:40.542Z

Link: CVE-2026-60519

cve-icon Vulnrichment

Updated: 2026-07-24T15:40:00.138Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:15:03Z

Weaknesses