Junglewise Threat Intelligence

CVE-2026-60428: Oracle Unified Directory unauthorized data access in OUD Core

CVE-2026-60428 · Severity: high · CVSS 8.2 · Published 2026-07-21

Technologies: Oracle Unified Directory. Vendors: Oracle.

Executive brief

Oracle Unified Directory, a central service used for managing user identities and directory information, contains a security vulnerability. An unauthorized attacker can exploit this over the network to gain full access to sensitive identity data or modify directory records. This could lead to significant data breaches or unauthorized changes to user accounts and permissions.

Technical details

A vulnerability in the OUD Core component of Oracle Unified Directory allows for unauthorized data access and modification. The flaw is exploitable by an unauthenticated attacker with network access via the LDAP protocol. The vulnerability is characterized by low attack complexity and requires no user interaction. Successful exploitation results in a high impact on confidentiality, allowing access to all accessible data, and a low impact on integrity, allowing for unauthorized updates, inserts, or deletes of some data. Affected versions include 12.2.1.4.0 and 14.1.2.1.0.

Affected products

  • Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
  • 2026-07-21: disclosed: NVD published the CVE record.

References

Related threats