Executive brief
Oracle Unified Directory is a comprehensive directory solution used to manage identity data across an enterprise. A critical vulnerability allows an unauthenticated attacker to remotely take full control of the directory service over the network. This could lead to the total compromise of user identity data, unauthorized access to integrated systems, and a complete disruption of authentication services.
Technical details
A vulnerability in the OUD Core component of Oracle Unified Directory (versions 12.2.1.4.0 and 14.1.2.1.0) is classified as Improper Access Control (CWE-284). The flaw is easily exploitable by an unauthenticated attacker with network access via the Remote Method Invocation (RMI) protocol. Successful exploitation allows for a complete takeover of the Oracle Unified Directory instance, impacting confidentiality, integrity, and availability. Security administrators should apply the relevant patches from the Oracle June 2026 Critical Patch Update.
Affected products
- Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle June 2026 Critical Patch Update published