Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Oracle Unified Directory Core component allows a low‑privileged attacker with network access to LDAP to compromise the directory service, potentially leading to full control over the system. The flaw results in severe confidentiality, integrity, and availability impacts, and is categorized as a CWE‑284 issue of improper access control. Successful exploitation can enable an attacker to modify, delete, or exfiltrate directory data, and to serve as a pivot point for further intrusions.

Affected Systems

Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0 are affected. These are part of Oracle Fusion Middleware and may be integrated with other Oracle products, so a breach of the directory can propagate to additional services.

Risk and Exploitability

The CVSS v3.1 score of 8.5 indicates high severity, and the attack vector is inferred to be remote over LDAP, requiring network access but no elevated privileges. The EPSS score is currently not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. Due to the potential for complete takeover and the scope change to other products, the risk remains high for any organization running the impacted versions and exposed to LDAP traffic.

Generated by OpenCVE AI on August 18, 2026 at 23:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch for Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0
  • Restrict LDAP traffic to trusted hosts or IP ranges using firewall or security groups
  • Configure directory services to enforce strict access control and least‑privilege policies

Generated by OpenCVE AI on August 18, 2026 at 23:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege LDAP Attack Enables Takeover of Oracle Unified Directory
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:13.537Z

Reserved: 2026-07-08T15:51:55.594Z

Link: CVE-2026-60841

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:44.750

Modified: 2026-08-18T21:16:44.750

Link: CVE-2026-60841

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:45:16Z

Weaknesses