CVE-2026-60361

Oracle · Oracle Unified Directory

A critical vulnerability in Oracle Unified Directory allows an authenticated attacker with low privileges to achieve full system compromise via network access.

Executive summary

A critical vulnerability in Oracle Unified Directory allows authenticated network attackers to achieve a full system takeover.

Vulnerability

This is an easily exploitable flaw in the OUD Core component that allows an attacker with low-level administrative credentials and network access via LDAP to compromise the directory server. The vulnerability allows for scope changes, meaning the impact can extend beyond the directory service to other integrated infrastructure components.

Business impact

With a CVSS score of 9.9, this vulnerability represents an extreme risk to organizational security. Successful exploitation grants an attacker full control over the directory service, which typically acts as a central identity provider. This could lead to a massive breach of user credentials, unauthorized access to connected enterprise applications, and a complete loss of confidentiality, integrity, and availability for the entire identity management infrastructure.

Remediation

Immediate Action: Administrators must apply the latest Oracle Critical Patch Update (CPU) available at the official Oracle Security Alerts website.

Proactive Monitoring: Monitor LDAP traffic for unusual authentication patterns or unauthorized administrative queries originating from low-privileged accounts.

Compensating Controls: Implement strict network segmentation to restrict access to the LDAP service to known, trusted management hosts only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of this identity-based vulnerability and the potential for a full system takeover, immediate patching is required. Organizations should prioritize this update in their next maintenance cycle to prevent unauthorized access to core directory services.