PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60424 Oracle CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:44.797Z and has not been modified since then. Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).

Vendor
Oracle
Product
Unified Directory
CVSS
CRITICAL 9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-29
Advisory published
2026-07-21
Advisory updated
2026-07-29

Who should care

Administrators of Oracle Unified Directory, Security teams responsible for Oracle Fusion Middleware, IT personnel managing network access and LDAP services, and vulnerability management teams should be aware of this critical vulnerability and take immediate action to protect their environments.

Technical summary

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).

Defensive priority

Oracle Unified Directory vulnerability with a CVSS score of 9.0 allows unauthenticated attackers with network access via LDAP to compromise the product, potentially impacting additional products.

Recommended defensive actions

  • Inventory Oracle Unified Directory installations for versions 12.2.1.4.0 and 14.1.2.1.0
  • Apply vendor patches or updates as available
  • Monitor LDAP traffic for suspicious activity
  • Implement compensating controls to limit network access to Oracle Unified Directory
  • Review and update security configurations for Oracle Unified Directory
  • Conduct a thorough review of the security posture of Oracle Unified Directory installations
  • Verify that network access controls are properly configured to restrict access to LDAP services

Evidence notes

The vulnerability is in Oracle Unified Directory, affecting versions 12.2.1.4.0 and 14.1.2.1.0. CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H. Evidence from CVE and NVD indicates that this is a critical vulnerability with high impacts on confidentiality, integrity, and availability. Defenders should verify the presence of affected versions in their environment and review network access controls to LDAP services.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-60424 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-60424

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-60424 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60424

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.