Executive brief
Oracle Unified Directory, a central platform for managing digital identities and directory services, contains a vulnerability that could allow an unauthorized user to take full control of the system. An attacker with low-level access to the network can exploit this flaw to compromise the directory, potentially leading to the theft of sensitive identity data or a total service outage. This poses a significant risk to corporate authentication systems and overall data integrity.
Technical details
A vulnerability exists in the OUD Core component of Oracle Unified Directory. The flaw is categorized as easily exploitable, requiring only low-privileged user credentials and network access via the LDAP protocol. Successful exploitation allows an attacker to achieve a complete takeover of the Oracle Unified Directory instance, impacting confidentiality, integrity, and availability. The vulnerability affects supported versions 12.2.1.4.0 and 14.1.2.1.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published