Junglewise Threat Intelligence

CVE-2026-60429: Oracle Unified Directory compromise in OUD Core

CVE-2026-60429 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Technologies: Oracle Unified Directory. Vendors: Oracle.

Executive brief

Oracle Unified Directory, a central service used for managing user identities and access across an organization, contains a critical security flaw. A user with very basic access to the corporate network can exploit this weakness to take full control of the directory service. This could allow an attacker to access sensitive user data, disrupt business operations, or gain unauthorized access to other connected systems.

Technical details

A critical vulnerability exists in the OUD Core component of Oracle Unified Directory (versions 12.2.1.4.0 and 14.1.2.1.0). The flaw is easily exploitable by a low-privileged attacker with network access via the LDAP protocol. Successful exploitation results in a complete takeover of the Oracle Unified Directory instance. Notably, the vulnerability involves a 'scope change' (CVSS S:C), meaning a successful attack can impact the security of other products and systems that rely on the directory for authentication or authorization. The vulnerability affects confidentiality, integrity, and availability. Users should refer to the Oracle July 2026 Critical Patch Update for remediation guidance.

Affected products

  • Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats