Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Unified Directory product contains a flaw that permits a low‑privileged attacker with network access through LDAP to fully compromise the directory service. The vulnerability can be exploited remotely, and successful attacks can lead to a complete takeover of the directory, resulting in a full loss of confidentiality, integrity, and availability. The CVSS 3.1 base score of 8.5 indicates a high‑severity flaw, and the vector shows that the attack requires an external network connection, high authentication complexity, low privileges, no user interaction, and a scope change that may affect other products. The description explicitly states that "Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory," underscoring the critical impact.

Affected Systems

This issue affects Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0, which are components of Oracle Fusion Middleware. The CWE is not specified, but the vulnerability is linked to improper access control in the LDAP component. Attackers need only network connectivity to the LDAP service of the affected Oracle Unified Directory instance. The product is developed by Oracle Corporation.

Risk and Exploitability

The CVSS score of 8.5 indicates a high likelihood of severe impact if exploited. No EPSS score is available, and the vulnerability is not listed in CISA KEV at the time of this analysis. Because the flaw can be triggered by a low‑privileged actor with simple LDAP access, the exploitation could be relatively straightforward for threat actors who can reach the LDAP endpoint. The scope shift implies that a successful compromise could also affect other products or services that rely on the same directory. Overall, the risk is significant, and organizations should treat this as a critical threat until a vendor fix is applied.

Generated by OpenCVE AI on August 18, 2026 at 23:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch that addresses this vulnerability
  • Restrict LDAP network access to trusted hosts and networks only
  • Configure firewall or ACL rules to limit incoming LDAP connections
  • Monitor LDAP logs for anomalous activity and investigate suspicious connections

Generated by OpenCVE AI on August 18, 2026 at 23:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege LDAP Attack Enables Full Oracle Unified Directory Takeover
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:13.857Z

Reserved: 2026-07-08T15:51:55.596Z

Link: CVE-2026-60849

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:44.877

Modified: 2026-08-18T21:16:44.877

Link: CVE-2026-60849

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:45:16Z

Weaknesses