Executive brief
Oracle Unified Directory, a central service used for managing user identities and directory information, contains a critical vulnerability. An unauthenticated attacker could exploit this over the network to take full control of the directory service. Because this service often manages access for other corporate systems, a successful attack could have a cascading impact on the security of multiple integrated applications and data.
Technical details
A vulnerability in the OUD Core component of Oracle Unified Directory (versions 12.2.1.4.0 and 14.1.2.1.0) allows an unauthenticated attacker with network access via LDAP to compromise the system. The exploit is characterized as having high complexity (AC:H) but results in a scope change (S:C), meaning the impact can extend beyond the directory service itself to other products relying on it for authentication or authorization. Successful exploitation grants the attacker full control over the Confidentiality, Integrity, and Availability of the service. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory