Junglewise Threat Intelligence

CVE-2026-60430: Oracle Unified Directory takeover in OUD Core

CVE-2026-60430 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Unified Directory. Vendors: Oracle.

Executive brief

Oracle Unified Directory, a directory service used for managing identity and access across enterprise environments, contains a vulnerability that could allow an unauthorized takeover. An attacker with low-level access to the network could exploit this flaw to gain full control over the directory service. This could lead to the theft of sensitive identity data, disruption of authentication services, and unauthorized access to other corporate systems relying on the directory.

Technical details

A vulnerability exists in the OUD Core component of Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0. The flaw is categorized as easily exploitable and requires only low-privileged credentials to execute over a network via the LDAP protocol. Successful exploitation allows an attacker to compromise the entire OUD instance, leading to a total loss of confidentiality, integrity, and availability (CVSS 8.8). Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
  • 2026-07-21: disclosed: CVE-2026-60430 was published to the NVD.

References

Related threats