Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-60429: Oracle Unified Directory: Unsecured LDAP Access Allows Takeover
CVE-2026-60429
Summary
A security weakness in Oracle Unified Directory makes it possible for an unauthorized user with access to the directory via the LDAP network protocol to gain control of the system. This could allow them to access or modify sensitive information, disrupt services, or even delete data. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. To protect your system, consider updating to a patched version or seeking assistance from Oracle support.
Original title
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vul...
Original description
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
nvd CVSS3.1
9.9
Vulnerability type
CWE-284
Improper Access Control
Published: 21 Jul 2026 · Updated: 25 Jul 2026 · First seen: 24 Jul 2026