Junglewise Threat Intelligence

CVE-2026-60421: Oracle Unified Directory security bypass in OUD Core

CVE-2026-60421 · Severity: high · CVSS 8.2 · Published 2026-07-21

Technologies: Oracle Unified Directory. Vendors: Oracle.

Executive brief

Oracle Unified Directory, a central service used for managing user identities and access across an organization, contains a security vulnerability. A user with low-level access could exploit this flaw to view, modify, or delete sensitive directory data. This could lead to unauthorized access to other corporate systems that rely on this directory for security.

Technical details

A vulnerability exists in the OUD Core component of Oracle Unified Directory (versions 12.2.1.4.0 and 14.1.2.1.0). The flaw is exploitable by a low-privileged attacker with network access via the LDAP protocol. While the attack complexity is high, a successful exploit results in a scope change (S:C), potentially impacting integrated products that rely on the directory service. Attackers can achieve full confidentiality and integrity compromise, allowing for the unauthorized creation, deletion, or modification of all accessible directory data. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.

Affected products

  • Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats