Executive brief
Oracle Unified Directory, a central service used for managing user identities and access across an organization, contains a high-severity vulnerability. An attacker could exploit this to gain full access to sensitive identity data or modify user records, potentially leading to unauthorized access to other connected corporate systems. While the attack is complex to execute, a successful breach could compromise the integrity of the entire identity management infrastructure.
Technical details
A vulnerability exists in the OUD Core component of Oracle Unified Directory (versions 12.2.1.4.0 and 14.1.2.1.0). The flaw is exploitable by an unauthenticated attacker via the LDAP protocol over a network. Although the attack complexity is rated as high, a successful exploit results in a scope change (S:C), meaning the impact can extend beyond the directory service itself to other integrated systems. Attackers can achieve unauthorized creation, deletion, or modification of all data within the directory, as well as complete read access to sensitive information. The vulnerability primarily impacts confidentiality and integrity, with no reported impact on availability.
Affected products
- Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle via NVD and July 2026 CPU.