Junglewise Threat Intelligence

CVE-2026-60426: Oracle Unified Directory unauthorized data access in OUD Core

CVE-2026-60426 · Severity: high · CVSS 8.5 · Published 2026-07-21

Technologies: Oracle Unified Directory. Vendors: Oracle.

Executive brief

Oracle Unified Directory, a central service used for managing user identities and access across an organization, contains a security vulnerability. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive directory data or modify records. This could lead to a significant breach of user privacy and potentially impact other corporate systems that rely on this directory for authentication.

Technical details

A vulnerability exists in the OUD Core component of Oracle Unified Directory (versions 12.2.1.4.0 and 14.1.2.1.0). The flaw is easily exploitable by a low-privileged attacker with network access via the LDAP protocol. Successful exploitation results in a 'scope change' (S:C), meaning the impact can extend beyond the directory service itself to other products in the environment. Attackers can achieve unauthorized read access to all directory data and perform unauthorized updates, inserts, or deletions of certain data records. The vulnerability was disclosed as part of the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats