Junglewise Threat Intelligence

CVE-2026-60437: Oracle Unified Directory integrity and availability loss in OUD Core

CVE-2026-60437 · Severity: high · CVSS 8.7 · Published 2026-07-21

Technologies: Oracle Unified Directory. Vendors: Oracle.

Executive brief

Oracle Unified Directory, a central service for managing user identities and access across an organization, contains a vulnerability that could allow a high-privileged user to compromise the system. An attacker could delete or modify critical identity data or cause a complete service outage, potentially impacting other connected business applications. This could lead to significant operational disruptions and unauthorized changes to user permissions.

Technical details

A vulnerability in the OUD Core component of Oracle Unified Directory (versions 12.2.1.4.0 and 14.1.2.1.0) allows a high-privileged attacker with network access via LDAP to compromise the directory service. The exploit is characterized as easily exploitable and results in a scope change, meaning the impact can extend beyond the OUD service itself to other integrated products. Successful exploitation can lead to unauthorized creation, deletion, or modification of all accessible data, as well as the ability to cause a persistent hang or repeatable crash (Denial of Service). The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0

Timeline

  • 2026-07-21: advisory: Initial publication of CVE-2026-60437 by Oracle

References

Related threats