Junglewise Threat Intelligence

CVE-2026-60359: Oracle Unified Directory information disclosure in OUD Core

CVE-2026-60359 · Severity: high · CVSS 8.6 · Published 2026-07-21

Technologies: Oracle Unified Directory. Vendors: Oracle.

Executive brief

Oracle Unified Directory, a central platform for managing identity data across an enterprise, contains a vulnerability that allows unauthorized individuals to access sensitive information. An attacker can exploit this over the network without needing a username or password. This could lead to the exposure of critical identity data and potentially impact other integrated business systems that rely on this directory service.

Technical details

A vulnerability in the OUD Core component of Oracle Unified Directory (versions 12.2.1.4.0 and 14.1.2.1.0) allows for unauthorized data access. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation results in a scope change (S:C), meaning the impact can extend beyond the directory service itself to other products in the environment. The primary impact is a total loss of confidentiality (C:H) for all data accessible via the directory. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats