Executive brief
Oracle Unified Directory, a service used to manage identity and directory information across an organization, contains a security flaw that allows unauthorized individuals to access the system over the network. An attacker could use this to delete or change sensitive corporate data, view private information, or disrupt the availability of the directory service. This could lead to significant operational disruption and the compromise of user account data.
Technical details
An improper access control vulnerability (CWE-284) exists in the OUD Core component of Oracle Unified Directory. The flaw is easily exploitable by an unauthenticated attacker with network access via the LDAP protocol. Successful exploitation allows an attacker to perform unauthorized creation, deletion, or modification of critical directory data, as well as gain read access to a subset of data and cause a partial denial of service. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. Users should refer to the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle June 2026 Critical Patch Update published