SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60361 2026-07-21

Oracle Unified Directory Takeover Flaw: CVE-2026-60361 (CVSS 9.9)

"A critical, network-exploitable vulnerability in Oracle Unified Directory allows a low-privileged attacker to fully compromise the directory service via LDAP, with impact spilling over into other connected products."

A critical, network-exploitable vulnerability in Oracle Unified Directory allows a low-privileged attacker to fully compromise the directory service via LDAP, with impact spilling over into other connected products.

What Is It

CVE-2026-60361 is a critical vulnerability in the OUD Core component of Oracle Unified Directory, part of Oracle Fusion Middleware. Oracle rates it CVSS 3.1 base score 9.9 (Critical), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The flaw is described as easily exploitable: an attacker with only low privileges and network access over LDAP can compromise the product. Successful exploitation results in full takeover of Oracle Unified Directory, with high confidentiality, integrity, and availability impact.

Why It Matters

The vulnerability carries a scope change (S:C), meaning that although the weakness resides in Oracle Unified Directory, attacks "may significantly impact additional products" beyond the vulnerable component itself. Because OUD is a directory and identity service, a takeover can cascade into systems that rely on it for authentication and directory data. The combination of low attack complexity, low required privileges, no user interaction, and network reachability over LDAP makes this an attractive target. Note: the supplied CISA KEV data is empty, so there is no confirmation of active exploitation in the source material.

What's Vulnerable

Patch Status

The vulnerability was published as part of the Oracle Critical Patch Update for July 2026 (source identifier: [email protected]). Administrators should consult the Oracle CPU July 2026 advisory and apply the corresponding fixes for the affected 12.2.1.4.0 and 14.1.2.1.0 releases. No CISA KEV required-action or due date is present in the supplied data.

Sources