Executive brief
Oracle Unified Directory, a central service used for managing user identities and directory information, contains a vulnerability that could allow an unauthorized person to take full control of the system. An attacker could potentially access, modify, or delete sensitive identity data, which could lead to widespread service disruptions or unauthorized access to other corporate systems. While the attack is difficult to execute, it can be performed remotely over the network without needing any valid login credentials.
Technical details
A vulnerability in the OUD Core component of Oracle Unified Directory (versions 12.2.1.4.0 and 14.1.2.1.0) allows an unauthenticated attacker with network access via the LDAP protocol to compromise the system. The exploit is characterized as having high complexity (AC:H), suggesting specific timing or environmental conditions are required for success. If successfully exploited, the attacker can achieve a complete takeover of the Oracle Unified Directory, resulting in a total loss of confidentiality, integrity, and availability. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.