CVE-2026-60419

Oracle · Unified Directory

A vulnerability in the Oracle Unified Directory (OUD) Core component allows a low privileged attacker to compromise the directory server via LDAP.

Executive summary

An easily exploitable vulnerability in Oracle Unified Directory allows authenticated attackers to gain unauthorized control over the directory services.

Vulnerability

This vulnerability affects the OUD Core component and allows a low privileged attacker with LDAP network access to execute commands or manipulate directory data, ultimately leading to a full system takeover.

Business impact

A compromise of Oracle Unified Directory is critical as it often serves as a centralized identity and access management repository. A CVSS score of 8.8 reflects the high severity, as an attacker gaining control of the directory could potentially escalate privileges, access sensitive identity data, or disrupt authentication services across the entire enterprise.

Remediation

Immediate Action: Apply the security patches provided in the July 2026 Oracle Critical Patch Update to all affected OUD instances.

Proactive Monitoring: Monitor LDAP traffic and server logs for unusual bind requests or administrative actions performed by low privileged accounts.

Compensating Controls: Implement strict network access control lists (ACLs) to ensure only authorized clients can communicate with the LDAP interface of the Unified Directory server.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Security teams should treat this vulnerability with high urgency. Because OUD is a foundational component for identity management, patching should be performed during the next maintenance window or immediately if the directory is exposed to broader network segments.