Executive brief
Oracle Unified Directory is a directory service used to manage identity and access across an organization. A vulnerability in the OUD Core component allows a high-privileged user to fully compromise the directory service over the network. This could lead to a complete takeover of the identity management system, impacting the confidentiality and integrity of all stored user data.
Technical details
This vulnerability affects the OUD Core component of Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0. It is classified as an easily exploitable flaw that requires high privileges (PR:H) and network access via the LDAP protocol. A successful exploit allows an attacker to compromise the entire Oracle Unified Directory instance, resulting in a complete loss of confidentiality, integrity, and availability (C:H/I:H/A:H). The vulnerability was disclosed as part of the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: disclosed: Initial disclosure in Oracle Critical Patch Update