Executive brief
Oracle Unified Directory, a central service for managing user identities and access across an organization, contains a security vulnerability. An attacker with basic network access and low-level user credentials can exploit this flaw to view, change, or delete sensitive identity data. This could lead to unauthorized access to corporate systems or the corruption of critical user directories.
Technical details
A vulnerability exists in the OUD Core component of Oracle Unified Directory (versions 12.2.1.4.0 and 14.1.2.1.0). The flaw is categorized as easily exploitable and requires only low-privileged authentication and network access via the LDAP protocol. Successful exploitation allows an attacker to achieve unauthorized creation, deletion, or modification of all data accessible to the directory, as well as complete read access to sensitive information. The vulnerability impacts both confidentiality and integrity but does not directly affect service availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.
Affected products
- Oracle Unified Directory 12.2.1.4.0, 14.1.2.1.0
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD