A critical (CVSS 9.9) vulnerability in Oracle Unified Directory lets a low-privileged network attacker fully compromise the directory over LDAP, with impact that spreads beyond the affected product.
What Is It
CVE-2026-60422 is a vulnerability in the OUD Core component of Oracle Unified Directory, part of Oracle Fusion Middleware. Per Oracle's advisory, the flaw is "easily exploitable" and allows a low-privileged attacker with network access via LDAP to compromise Oracle Unified Directory. It carries a CVSS 3.1 base score of 9.9 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L, network attack vector, low complexity, low privileges required, no user interaction, and a changed scope.
Why It Matters
The scope-change designation is the key detail: while the vulnerability resides in Oracle Unified Directory, Oracle states that attacks "may significantly impact additional products." Successful exploitation can result in unauthorized creation, deletion, or modification of critical data (or all OUD-accessible data), complete unauthorized read access to all OUD-accessible data, and a partial denial of service. Because Oracle Unified Directory is an identity/directory service, compromise of this component can undermine authentication and data integrity across dependent systems. The combination of low privileges required, no user interaction, and network reachability over LDAP makes this an attractive target.
What's Vulnerable
The supported affected version is Oracle Unified Directory 14.1.2.1.0 (Oracle Fusion Middleware, OUD Core component), per Oracle's record. No other versions are listed in the supplied source material.
Patch Status
Oracle addresses this issue in its July 2026 Critical Patch Update. Organizations running the affected version should apply the fixes referenced in Oracle's Critical Patch Update advisory. There is no CISA KEV entry in the supplied source material, so active exploitation is not confirmed by KEV data at this time.