Junglewise Threat Intelligence

CVE-2026-60425: Oracle Unified Directory denial of service in OUD Core

CVE-2026-60425 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Oracle Unified Directory. Vendors: Oracle.

Executive brief

Oracle Unified Directory, a directory service used for managing identity and access across enterprise environments, is vulnerable to a denial-of-service attack. An unauthenticated attacker can remotely send malicious LDAP requests to cause the service to hang or crash repeatedly. This can disrupt user authentication and other critical business operations that rely on the directory service.

Technical details

A vulnerability in the OUD Core component of Oracle Unified Directory allows for a denial-of-service (DoS) attack. The flaw is easily exploitable by an unauthenticated attacker with network access via the LDAP protocol. Successful exploitation results in a hang or a frequently repeatable crash of the OUD service, impacting availability. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats