PatchSiren cyber security CVE debrief
CVE-2026-46774 Oracle Corporation CVE debrief
A critical vulnerability, CVE-2026-46774, was discovered in Oracle Unified Directory, a component of Oracle Fusion Middleware. The vulnerability has a CVSS score of 9.8 and allows unauthenticated attackers with network access via RMI to compromise the directory, potentially leading to a complete takeover. The vulnerability is located in the OUD Core component and is easily exploitable. Administrators and security teams should prioritize patching to prevent takeovers.
- Vendor
- Oracle Corporation
- Product
- Oracle Unified Directory
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-19
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-19
Who should care
Administrators and security teams responsible for Oracle Unified Directory installations should prioritize patching this vulnerability to prevent potential takeovers. This includes teams managing Oracle Fusion Middleware, specifically those with OUD Core component deployments. Security teams should assess their exposure and plan for immediate remediation due to the critical severity and potential for complete takeover.
Technical summary
The vulnerability is located in the OUD Core component of Oracle Unified Directory, a part of Oracle Fusion Middleware. It is easily exploitable and allows unauthenticated attackers with network access via RMI to compromise Oracle Unified Directory. Successful attacks can result in a complete takeover of Oracle Unified Directory. The CVSS 3.1 Base Score is 9.8, indicating a Critical severity level. This vulnerability affects Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0.
Defensive priority
High
Recommended defensive actions
- Apply the security patch provided by Oracle Corporation
- Restrict network access to Oracle Unified Directory
- Monitor for suspicious RMI activity
- Review and update access controls for Oracle Unified Directory
- Perform vulnerability scanning to identify exposed systems
- Implement compensating controls for exposed systems while remediation is scheduled
- Track exceptions and retest remediated assets
Evidence notes
The CVE record was published on 2026-06-17T10:53:54.943Z and was last modified on 2026-06-19T06:17:08.030Z. The NVD entry is currently Analyzed. The vulnerability affects Oracle Unified Directory, specifically the OUD Core component. The CVE record and NVD entry provide additional context and details about the vulnerability. Evidence is based on the NVD entry and the CVE record.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46774 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46774
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46774 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46774
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspujun2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.