Executive brief
Oracle Unified Directory, a central service used for managing user identities and directory information, contains a critical security flaw. An unauthorized person can access the system over the network without a password and take complete control of the directory. This could lead to the theft of sensitive user data, unauthorized changes to identity records, or a total shutdown of authentication services.
Technical details
A critical vulnerability exists in the OUD Core component of Oracle Unified Directory (versions 12.2.1.4.0 and 14.1.2.1.0). The flaw is categorized as an improper access control issue (CWE-284) that is easily exploitable over the network via the LDAP protocol. An unauthenticated attacker can exploit this vulnerability without any user interaction to gain full control over the directory service. This results in a total loss of confidentiality, integrity, and availability (CVSS 9.8). Users are advised to consult the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle June 2026 Critical Patch Update published