PatchSiren cyber security CVE debrief
CVE-2026-60914 Oracle CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:47.347Z and has not been modified since then. CVE-2026-60914 is a vulnerability in Oracle Unified Directory, a component of Oracle Fusion Middleware. The vulnerability is in the OUD Core and affects versions 12.2.1.4.0 and 14.1.2.1.0. It allows unauthenticated attackers with network access via LDAP to compromise Oracle Unified Directory, potentially leading to unauthorized access to critical data. The CVSS 3.1 Base Score is 7.5, indicating a high confidentiality impact. Security teams should prioritize patching and take immediate action to protect against potential data breaches. Organizations should verify Oracle Unified Directory deployments, review LDAP access controls, and monitor for unauthorized data access attempts.
- Vendor
- Oracle
- Product
- Unified Directory
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-08-21
Who should care
Organizations using Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0 should prioritize patching this vulnerability. Security teams and administrators responsible for Oracle Fusion Middleware and Unified Directory should be aware of this high-severity vulnerability and take immediate action to protect against potential data breaches. IT managers and cybersecurity professionals should review Oracle Unified Directory deployments and ensure that security controls are in place to mitigate the risk of unauthorized data access.
Technical summary
CVE-2026-60914 is a vulnerability in Oracle Unified Directory, a component of Oracle Fusion Middleware. The vulnerability is in the OUD Core and affects versions 12.2.1.4.0 and 14.1.2.1.0. It allows unauthenticated attackers with network access via LDAP to compromise Oracle Unified Directory, potentially leading to unauthorized access to critical data. The CVSS 3.1 Base Score is 7.5, indicating a high confidentiality impact. Security teams should prioritize patching and take immediate action to protect against potential data breaches.
Defensive priority
Oracle Unified Directory vulnerability allows unauthenticated network attackers to access critical data; prioritize patching for high confidentiality impact.
Recommended defensive actions
- Apply Oracle patch for CVE-2026-60914
- Verify and update Oracle Unified Directory to a patched version
- Restrict LDAP access to trusted networks
- Monitor for unauthorized data access
- Review and update security controls for Oracle Fusion Middleware
- Conduct a thorough review of Oracle Unified Directory configurations and deployments
- Perform vulnerability scanning and penetration testing to identify potential exposure
Evidence notes
Official CVE and NVD records confirm vulnerability in Oracle Unified Directory; verify affected versions 12.2.1.4.0 and 14.1.2.1.0; CVSS 3.1 score of 7.5 indicates high confidentiality impact. The vulnerability allows unauthenticated network attackers to access critical data. Security teams should verify Oracle Unified Directory deployments, review LDAP access controls, and monitor for unauthorized data access attempts.
Official resources
-
CVE-2026-60914 CVE record
CVE.org
-
CVE-2026-60914 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:47.347Z and has not been modified since then.