CVE-2026-60422
Oracle Unified Directory (OUD) version 14.1.2.1.0 has a critical vulnerability that lets a low‑privileged attacker with network access create, delete, or modify data, or cause a partial denial of service. The flaw can be exploited over LDAP and can affect other Oracle products as well.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Oracle Unified Directory (OUD) component of Oracle Fusion Middleware, version 14.1.2.1.0, used by organizations that manage directory services.
Real-world impact
An attacker could add, delete, or change directory entries, read sensitive data, or disrupt service for users, potentially compromising the entire directory infrastructure.
Why this severity
The CVSS score of 9.9 reflects that the vulnerability is network‑based, requires only low privileges, and can lead to high confidentiality and integrity loss with a partial availability impact.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 21, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 29, 2026 · 4d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- oracle.com/security-alerts/cpujul2026.…vendor advisory