Executive brief
Oracle Unified Directory, a central service used for managing user identities and access across an organization, contains a critical security flaw. A user with low-level access can exploit this vulnerability over the network to gain full control over identity data, including the ability to view, modify, or delete sensitive user records. This could lead to widespread unauthorized access to other corporate systems and cause partial service outages.
Technical details
A vulnerability in the OUD Core component of Oracle Unified Directory (version 14.1.2.1.0) allows for a scope-changing compromise via the LDAP protocol. The flaw is easily exploitable by a low-privileged attacker with network access, requiring no user interaction. Successful exploitation grants the attacker full read, write, and delete permissions over all directory data, potentially impacting integrated downstream products. Additionally, the attacker can trigger a partial denial of service (DoS). The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Unified Directory 14.1.2.1.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published