PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60914 Oracle CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:47.347Z and has not been modified since then. CVE-2026-60914 is a vulnerability in Oracle Unified Directory, a component of Oracle Fusion Middleware. The vulnerability is in the OUD Core and affects versions 12.2.1.4.0 and 14.1.2.1.0. It allows unauthenticated attackers with network access via LDAP to compromise Oracle Unified Directory, potentially leading to unauthorized access to critical data. The CVSS 3.1 Base Score is 7.5, indicating a high confidentiality impact. Security teams should prioritize patching and take immediate action to protect against potential data breaches. Organizations should verify Oracle Unified Directory deployments, review LDAP access controls, and monitor for unauthorized data access attempts.

Vendor
Oracle
Product
Unified Directory
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-08-21
Advisory published
2026-08-18
Advisory updated
2026-08-21

Who should care

Organizations using Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0 should prioritize patching this vulnerability. Security teams and administrators responsible for Oracle Fusion Middleware and Unified Directory should be aware of this high-severity vulnerability and take immediate action to protect against potential data breaches. IT managers and cybersecurity professionals should review Oracle Unified Directory deployments and ensure that security controls are in place to mitigate the risk of unauthorized data access.

Technical summary

CVE-2026-60914 is a vulnerability in Oracle Unified Directory, a component of Oracle Fusion Middleware. The vulnerability is in the OUD Core and affects versions 12.2.1.4.0 and 14.1.2.1.0. It allows unauthenticated attackers with network access via LDAP to compromise Oracle Unified Directory, potentially leading to unauthorized access to critical data. The CVSS 3.1 Base Score is 7.5, indicating a high confidentiality impact. Security teams should prioritize patching and take immediate action to protect against potential data breaches.

Defensive priority

Oracle Unified Directory vulnerability allows unauthenticated network attackers to access critical data; prioritize patching for high confidentiality impact.

Recommended defensive actions

  • Apply Oracle patch for CVE-2026-60914
  • Verify and update Oracle Unified Directory to a patched version
  • Restrict LDAP access to trusted networks
  • Monitor for unauthorized data access
  • Review and update security controls for Oracle Fusion Middleware
  • Conduct a thorough review of Oracle Unified Directory configurations and deployments
  • Perform vulnerability scanning and penetration testing to identify potential exposure

Evidence notes

Official CVE and NVD records confirm vulnerability in Oracle Unified Directory; verify affected versions 12.2.1.4.0 and 14.1.2.1.0; CVSS 3.1 score of 7.5 indicates high confidentiality impact. The vulnerability allows unauthenticated network attackers to access critical data. Security teams should verify Oracle Unified Directory deployments, review LDAP access controls, and monitor for unauthorized data access attempts.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:16:47.347Z and has not been modified since then.