Junglewise Threat Intelligence

CVE-2026-60418: Oracle Unified Directory compromise in OUD Core

CVE-2026-60418 · Severity: high · CVSS 7.2 · Published 2026-07-21

Technologies: Oracle Unified Directory. Vendors: Oracle.

Executive brief

Oracle Unified Directory, a comprehensive directory service for managing identities across enterprise applications, contains a vulnerability in its core component. A highly privileged attacker with network access can exploit this flaw to gain full control over the directory service. This could lead to a complete compromise of identity data, unauthorized modifications, and service outages, impacting the organization's authentication and authorization infrastructure.

Technical details

A vulnerability exists in the OUD Core component of Oracle Unified Directory (versions 12.2.1.4.0 and 14.1.2.1.0). The flaw is categorized as easily exploitable but requires high privileges (PR:H) for successful execution. An attacker can exploit this over the network via the LDAP protocol without requiring user interaction. Successful exploitation results in a complete compromise of the Oracle Unified Directory instance, impacting confidentiality, integrity, and availability. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed: CVE-2026-60418 was published to the NVD.

References

Related threats