PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60914 Oracle CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:47.347Z and has not been modified since then. CVE-2026-60914 is a vulnerability in Oracle Unified Directory, a component of Oracle Fusion Middleware. The vulnerability is in the OUD Core and affects versions 12.2.1.4.0 and 14.1.2.1.0. It allows unauthenticated attackers with network access via LDAP to compromise Oracle Unified Directory, potentially leading to unauthorized access to critical data. The CVSS 3.1 Base Score is 7.5, indicating a high confidentiality impact. Security teams should prioritize patching and take immediate action to protect against potential data breaches. Organizations should verify Oracle Unified Directory deployments, review LDAP access controls, and monitor for unauthorized data access attempts.

Vendor
Oracle
Product
Unified Directory
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-08-21
Advisory published
2026-08-18
Advisory updated
2026-08-21

Who should care

Organizations using Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0 should prioritize patching this vulnerability. Security teams and administrators responsible for Oracle Fusion Middleware and Unified Directory should be aware of this high-severity vulnerability and take immediate action to protect against potential data breaches. IT managers and cybersecurity professionals should review Oracle Unified Directory deployments and ensure that security controls are in place to mitigate the risk of unauthorized data access.

Technical summary

CVE-2026-60914 is a vulnerability in Oracle Unified Directory, a component of Oracle Fusion Middleware. The vulnerability is in the OUD Core and affects versions 12.2.1.4.0 and 14.1.2.1.0. It allows unauthenticated attackers with network access via LDAP to compromise Oracle Unified Directory, potentially leading to unauthorized access to critical data. The CVSS 3.1 Base Score is 7.5, indicating a high confidentiality impact. Security teams should prioritize patching and take immediate action to protect against potential data breaches.

Defensive priority

Oracle Unified Directory vulnerability allows unauthenticated network attackers to access critical data; prioritize patching for high confidentiality impact.

Recommended defensive actions

  • Apply Oracle patch for CVE-2026-60914
  • Verify and update Oracle Unified Directory to a patched version
  • Restrict LDAP access to trusted networks
  • Monitor for unauthorized data access
  • Review and update security controls for Oracle Fusion Middleware
  • Conduct a thorough review of Oracle Unified Directory configurations and deployments
  • Perform vulnerability scanning and penetration testing to identify potential exposure

Evidence notes

Official CVE and NVD records confirm vulnerability in Oracle Unified Directory; verify affected versions 12.2.1.4.0 and 14.1.2.1.0; CVSS 3.1 score of 7.5 indicates high confidentiality impact. The vulnerability allows unauthenticated network attackers to access critical data. Security teams should verify Oracle Unified Directory deployments, review LDAP access controls, and monitor for unauthorized data access attempts.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-60914 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-60914

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-60914 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60914

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.