A CVSS 10.0 flaw in Oracle Unified Directory lets an unauthenticated attacker fully compromise the LDAP directory over the network, with scope-changing impact that can reach beyond the product itself.
What Is It
CVE-2026-60360 is a critical vulnerability in the OUD Core component of Oracle Unified Directory, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful exploitation can result in a full takeover of the directory. The vulnerability carries a CVSS 3.1 base score of 10.0 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, network-reachable, low complexity, no privileges, and no user interaction required.
Why It Matters
This is a maximum-severity issue. The attack requires no authentication and no user interaction, and it delivers high confidentiality, integrity, and availability impact. Critically, the CVSS scope is Changed: while the vulnerability lives in Oracle Unified Directory, Oracle notes that attacks "may significantly impact additional products." Because OUD serves as an LDAP directory and identity backbone, a takeover can cascade into systems that depend on it for authentication and directory services.
What's Vulnerable
- Product: Oracle Unified Directory (Oracle Fusion Middleware)
- Component: OUD Core
- Affected versions: 12.2.1.4.0 and 14.1.2.1.0
- Attack path: Network access via LDAP, unauthenticated
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Administrators running the affected versions should apply the fixes from that Critical Patch Update without delay. No CISA KEV entry accompanied this source material, so there is no confirmation of active exploitation at this time; given the 10.0 severity and unauthenticated network vector, prompt patching is strongly advised.