Executive brief
Oracle Unified Directory, a comprehensive directory service used for managing identity data across enterprises, contains a high-severity vulnerability. An attacker with low-level access to the network can exploit this flaw to take full control of the directory service. This could lead to the unauthorized access, modification, or deletion of sensitive identity and authentication data, potentially disrupting business operations and compromising user accounts.
Technical details
This vulnerability exists in the OUD Core component of Oracle Unified Directory. It is classified as easily exploitable, requiring only low-privileged authentication and network access via the LDAP protocol. The flaw allows an attacker to achieve a complete takeover of the Oracle Unified Directory instance, impacting confidentiality, integrity, and availability. The vulnerability affects supported versions 12.2.1.4.0 and 14.1.2.1.0. Users are advised to consult the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory