Junglewise Threat Intelligence

CVE-2026-60420: Oracle Unified Directory unauthorized data access in OUD Core

CVE-2026-60420 · Severity: high · CVSS 8.5 · Published 2026-07-21

Technologies: Oracle Unified Directory. Vendors: Oracle.

Executive brief

Oracle Unified Directory, a central service used for managing user identities and directory information, contains a vulnerability that allows an attacker to access or modify sensitive data. An individual with basic user credentials could exploit this over the network to gain unauthorized access to critical information or disrupt directory services. Because this component often integrates with other corporate systems, a successful attack could also impact the security of connected applications and services.

Technical details

A vulnerability exists in the OUD Core component of Oracle Unified Directory (versions 12.2.1.4.0 and 14.1.2.1.0). The flaw is categorized by a scope change (S:C), meaning an exploit can impact components beyond the immediate security scope of the OUD Core. An attacker with low-privileged credentials can exploit this vulnerability over the network via the LDAP protocol. Successful exploitation can lead to unauthorized read access to all directory data (Confidentiality: High) and unauthorized modification, insertion, or deletion of certain data (Integrity: Low). Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation guidance.

Affected products

  • Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats