Description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Unified Directory allows an attacker with low privileges and network access via LDAP to compromise the directory service. The flaw can be exploited relatively easily, enabling the attacker to obtain unauthorized access to critical data and, in some scenarios, full data sets. This vulnerability has a CVSS 3.1 base score of 7.7, with high confidentiality impact and a scope change indicating potential privilege escalation or cross‑component access.

Affected Systems

The affected product is Oracle Unified Directory from Oracle Corporation, specifically versions 12.2.1.4.0 and 14.1.2.1.0. These versions are part of Oracle Fusion Middleware and are used to provide LDAP and directory services primarily for authentication and authorization within corporate environments.

Risk and Exploitability

The exploit requires network connectivity to the LDAP port and no special pre‑existing access rights. While the EPSS score is less than 1%, the CVSS 7.7 rating and the scope change suggest a moderate‑to‑high risk for organizations that expose the UOD service to untrusted networks. The vulnerability is not currently listed on CISA’s KEV catalog. Attackers could leverage the issue to read sensitive directory entries, potentially enabling further attacks such as credential harvesting or account takeover.

Generated by OpenCVE AI on August 21, 2026 at 21:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s security patch for Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0 to remediate the LDAP authentication flaw.
  • Restrict LDAP traffic to trusted networks or enforce firewall rules that block open access to the UOD LDAP ports from external or untrusted sources.
  • Enable detailed audit logging for LDAP authentication attempts and review logs regularly to detect suspicious activity.

Generated by OpenCVE AI on August 21, 2026 at 21:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Low-Privileged LDAP Access Exploit in Oracle Unified Directory
Weaknesses CWE-287

Fri, 21 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Fri, 21 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Title Low-Privileged LDAP Access Exploit in Oracle Unified Directory
Weaknesses CWE-287

Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Unified Directory accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle unified Directory
CPEs cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle unified Directory
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Unified Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T16:47:10.852Z

Reserved: 2026-07-08T15:51:55.605Z

Link: CVE-2026-60969

cve-icon Vulnrichment

Updated: 2026-08-21T14:05:04.555Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:16:49.503

Modified: 2026-08-21T17:16:33.197

Link: CVE-2026-60969

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T22:00:14Z

Weaknesses