SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60362 2026-07-21

Oracle Unified Directory Hit by Critical Unauthenticated Takeover Flaw (CVE-2026-60362)

"A critical, easily exploitable vulnerability in Oracle Unified Directory lets an unauthenticated attacker take over the directory over the network via LDAP, earning a maximum-tier CVSS score of 9.8."

A critical, easily exploitable vulnerability in Oracle Unified Directory lets an unauthenticated attacker take over the directory over the network via LDAP, earning a maximum-tier CVSS score of 9.8.

What Is It

CVE-2026-60362 is a critical vulnerability in the OUD Core component of Oracle Unified Directory, part of Oracle Fusion Middleware. According to Oracle's advisory, the flaw is easily exploitable and allows an unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. A successful attack can result in full takeover of the product. It carries a CVSS 3.1 Base Score of 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Why It Matters

The vulnerability scores high across the board: network attack vector, low attack complexity, no privileges required, and no user interaction, combined with high impacts to confidentiality, integrity, and availability. Because Oracle Unified Directory serves as an identity and directory service, a takeover exposes the authentication backbone of an environment. The exploitability score is 3.9 (the maximum) and the impact score is 5.9. There is no confirmed CISA KEV entry for active exploitation in the supplied material.

What's Vulnerable

The affected product is Oracle Unified Directory (vendor: Oracle Corporation), component OUD Core. The supported versions listed as affected are:

The attack path is specifically LDAP-facing network access to the directory.

Patch Status

The vulnerability was published on 2026-07-21 with an NVD status of "Received." Oracle disclosed it through its July 2026 Critical Patch Update. Organizations running the affected versions should consult the Oracle Critical Patch Update advisory and apply the associated fixes. No CISA KEV required-action or due date is present in the supplied source material.

Sources