CVE-2026-60360
Oracle · Unified Directory
A critical vulnerability in the Oracle Unified Directory OUD Core allows unauthenticated, remote attackers to achieve a full system takeover via LDAP.
Executive summary
A critical, unauthenticated remote vulnerability in Oracle Unified Directory allows for total system takeover via the LDAP protocol.
Vulnerability
The vulnerability is located in the OUD Core component. It allows an unauthenticated attacker with network access to the LDAP service to fully compromise the directory server, enabling unauthorized access to stored identity data.
Business impact
A CVSS score of 10.0 reflects the extreme risk posed by this vulnerability. Successful exploitation grants the attacker full control over the directory service, allowing them to extract, modify, or delete identity information, which effectively compromises the security of every system that relies on the directory for authentication and authorization.
Remediation
Immediate Action: Apply the security patches provided in the July 2026 Oracle Critical Patch Update immediately.
Proactive Monitoring: Review LDAP traffic logs for unauthorized access attempts or suspicious queries that deviate from standard operational behavior.
Compensating Controls: Implement strict network-level access controls to limit LDAP connectivity to authorized clients and internal segments only, reducing the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the critical nature of the directory service, this vulnerability must be addressed with the highest urgency. Administrators should verify their versions of Oracle Unified Directory and apply the necessary patches as soon as they are made available by the vendor.