Executive brief
Oracle Unified Directory, a central service used for managing user identities and permissions, contains a critical security flaw. An unauthorized attacker can remotely take full control of the directory service over the network without needing a password. This could allow them to access sensitive user data, disrupt business operations, or gain unauthorized access to other connected corporate systems.
Technical details
A vulnerability in the OUD Core component of Oracle Unified Directory (versions 12.2.1.4.0 and 14.1.2.1.0) allows for complete system takeover. The flaw is exploitable by an unauthenticated attacker with network access via the LDAP protocol. The vulnerability is characterized by a 'Scope Change' (S:C), meaning a successful exploit can impact security components beyond the immediate Oracle Unified Directory environment. Oracle has addressed this in the July 2026 Critical Patch Update. The attack requires no user interaction and has low complexity.
Affected products
- Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory