Executive brief
Oracle Unified Directory, a central service used for managing user identities and access across an organization, contains a critical security vulnerability. A user with low-level access to the network can exploit this flaw to take complete control of the directory service. Because this system often manages permissions for many other applications, a successful attack could allow an unauthorized person to gain access to a wide range of corporate data and systems.
Technical details
A vulnerability in the OUD Core component of Oracle Unified Directory (versions 12.2.1.4.0 and 14.1.2.1.0) allows for a complete compromise of the application. The flaw is categorized as easily exploitable, requiring only low-privileged authentication and network access via the LDAP protocol. Notably, the vulnerability involves a 'scope change' (CVSS S:C), meaning a successful exploit can impact security components beyond the Oracle Unified Directory itself, potentially affecting integrated Fusion Middleware products. Attackers can achieve full unauthorized access to data (Confidentiality), modify directory information (Integrity), and cause service outages (Availability). Users should refer to the Oracle July 2026 Critical Patch Update for remediation.
Affected products
- Oracle Corporation Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: advisory: Initial publication by Oracle and NVD