Executive brief
Oracle Unified Directory, a central platform for managing digital identities and directory services, contains a critical security flaw. An unauthorized attacker can remotely access the system over the network to gain full control of the directory service. This could lead to a total compromise of user identity data, unauthorized access to connected business applications, and a complete shutdown of authentication services.
Technical details
A critical vulnerability exists in the OUD Core component of Oracle Unified Directory (versions 12.2.1.4.0 and 14.1.2.1.0). The flaw is classified as easily exploitable and allows an unauthenticated attacker with network access via the LDAP protocol to compromise the server. Successful exploitation results in a complete takeover of the Oracle Unified Directory instance, impacting confidentiality, integrity, and availability. The vulnerability has a CVSS 3.1 base score of 9.8. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD