SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60360 2026-07-21

CVE-2026-60360: Critical Unauthenticated Takeover in Oracle Unified Directory

"A CVSS 10.0 flaw in Oracle Unified Directory lets an unauthenticated attacker fully compromise the LDAP directory over the network, with scope-changing impact that can reach beyond the product itself."

A CVSS 10.0 flaw in Oracle Unified Directory lets an unauthenticated attacker fully compromise the LDAP directory over the network, with scope-changing impact that can reach beyond the product itself.

What Is It

CVE-2026-60360 is a critical vulnerability in the OUD Core component of Oracle Unified Directory, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful exploitation can result in a full takeover of the directory. The vulnerability carries a CVSS 3.1 base score of 10.0 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, network-reachable, low complexity, no privileges, and no user interaction required.

Why It Matters

This is a maximum-severity issue. The attack requires no authentication and no user interaction, and it delivers high confidentiality, integrity, and availability impact. Critically, the CVSS scope is Changed: while the vulnerability lives in Oracle Unified Directory, Oracle notes that attacks "may significantly impact additional products." Because OUD serves as an LDAP directory and identity backbone, a takeover can cascade into systems that depend on it for authentication and directory services.

What's Vulnerable

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Administrators running the affected versions should apply the fixes from that Critical Patch Update without delay. No CISA KEV entry accompanied this source material, so there is no confirmation of active exploitation at this time; given the 10.0 severity and unauthenticated network vector, prompt patching is strongly advised.

Sources