SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60429 2026-07-21

CVE-2026-60429: Critical Oracle Unified Directory Takeover Flaw

"A critical (CVSS 9.9) vulnerability in Oracle Unified Directory allows a low-privileged, network-based attacker to fully compromise the directory service via LDAP, with impact potentially spreading to other products."

A critical (CVSS 9.9) vulnerability in Oracle Unified Directory allows a low-privileged, network-based attacker to fully compromise the directory service via LDAP, with impact potentially spreading to other products.

What Is It

CVE-2026-60429 is a critical flaw in the OUD Core component of Oracle Unified Directory, part of Oracle Fusion Middleware. According to Oracle's advisory, the vulnerability is "easily exploitable" and lets a low-privileged attacker with network access via LDAP compromise Oracle Unified Directory. Successful attacks can result in a complete takeover of the product. Notably, the vulnerability carries a scope change; while it resides in Oracle Unified Directory, attacks may significantly impact additional products.

Why It Matters

The vulnerability holds a CVSS 3.1 base score of 9.9 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. This reflects network-based attack access, low attack complexity, only low privileges required, and no user interaction. Impacts to confidentiality, integrity, and availability are all rated HIGH. The combination of easy exploitability and the changed scope, meaning blast radius can extend beyond the directory itself, makes this a high-priority concern for any environment running the affected software as an identity backbone.

What's Vulnerable

The affected product is Oracle Unified Directory (component: OUD Core) within Oracle Fusion Middleware. Per the NVD record, the supported affected versions are:

Patch Status

Oracle addressed this vulnerability in its Critical Patch Update for July 2026. Administrators should consult the Oracle Critical Patch Update advisory (cpujul2026) and apply the relevant fixes for the affected Oracle Unified Directory versions. No CISA KEV entry confirming active exploitation was supplied with this source material.

Sources