Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-60361: Oracle Unified Directory: Unsecured Access via LDAP
CVE-2026-60361
CVE-2026-60361
Summary
Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0 are at risk. An attacker with network access can potentially take control of the directory. This could impact other connected systems, so it's essential to update or patch these versions to prevent unauthorized access.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| oracle corporation | oracle unified directory | 12.2.1.4.0 |
Original title
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vul...
Original description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
mitre CVSS3.1
9.9
- https://www.oracle.com/security-alerts/cpujul2026.html vendor-advisory
Published: 21 Jul 2026 · Updated: 25 Jul 2026 · First seen: 24 Jul 2026