SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60424 2026-07-21

CVE-2026-60424: Critical Oracle Unified Directory Takeover Flaw via LDAP

"Oracle's July 2026 Critical Patch Update discloses CVE-2026-60424, a critical (CVSS 9.0) flaw in Oracle Unified Directory that lets an unauthenticated network attacker take over the directory and potentially impact…"

Oracle's July 2026 Critical Patch Update discloses CVE-2026-60424, a critical (CVSS 9.0) flaw in Oracle Unified Directory that lets an unauthenticated network attacker take over the directory and potentially impact other products.

What Is It

CVE-2026-60424 is a vulnerability in the OUD Core component of Oracle Unified Directory, part of Oracle Fusion Middleware. An unauthenticated attacker with network access via LDAP can exploit the flaw to compromise Oracle Unified Directory. Although the vulnerability resides in Oracle Unified Directory, a successful attack causes a scope change, meaning it may significantly impact additional products beyond the vulnerable component. Successful exploitation can result in complete takeover of Oracle Unified Directory.

Why It Matters

The flaw carries a CVSS 3.1 base score of 9.0 (CRITICAL), with high impacts to confidentiality, integrity, and availability (vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H). It requires no privileges and no user interaction, and is exploitable remotely over the network via LDAP. While attack complexity is rated high, Oracle describes it as "difficult to exploit", the combination of unauthenticated network access, full takeover potential, and scope change makes this a serious risk for exposed directory infrastructure that underpins authentication and identity services.

What's Vulnerable

The affected product is Oracle Unified Directory (Oracle Fusion Middleware, OUD Core component). The supported versions listed as affected are:

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Administrators should apply the fixes provided in the Oracle Critical Patch Update Advisory referenced below. No CISA KEV entry or confirmation of active exploitation was supplied for this CVE.

Sources