PatchSiren cyber security CVE debrief
CVE-2026-60424 Oracle CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:44.797Z and has not been modified since then. Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
- Vendor
- Oracle
- Product
- Unified Directory
- CVSS
- CRITICAL 9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-29
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-29
Who should care
Administrators of Oracle Unified Directory, Security teams responsible for Oracle Fusion Middleware, IT personnel managing network access and LDAP services, and vulnerability management teams should be aware of this critical vulnerability and take immediate action to protect their environments.
Technical summary
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
Defensive priority
Oracle Unified Directory vulnerability with a CVSS score of 9.0 allows unauthenticated attackers with network access via LDAP to compromise the product, potentially impacting additional products.
Recommended defensive actions
- Inventory Oracle Unified Directory installations for versions 12.2.1.4.0 and 14.1.2.1.0
- Apply vendor patches or updates as available
- Monitor LDAP traffic for suspicious activity
- Implement compensating controls to limit network access to Oracle Unified Directory
- Review and update security configurations for Oracle Unified Directory
- Conduct a thorough review of the security posture of Oracle Unified Directory installations
- Verify that network access controls are properly configured to restrict access to LDAP services
Evidence notes
The vulnerability is in Oracle Unified Directory, affecting versions 12.2.1.4.0 and 14.1.2.1.0. CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H. Evidence from CVE and NVD indicates that this is a critical vulnerability with high impacts on confidentiality, integrity, and availability. Defenders should verify the presence of affected versions in their environment and review network access controls to LDAP services.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-60424 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-60424
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-60424 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60424
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cpujul2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.