criticalZero-Day

Oracle Unified Directory Unauthenticated LDAP Takeover (CVE-2026-60360)

First seen Jul 24, 2026 · Updated Jul 24, 2026 · CVSS 10

oracleldapdirectory-serviceunauthenticated-rceidentity-infrastructureagent-relevant

A maximum-severity vulnerability (CVSS 10.0) exists in Oracle Unified Directory's OUD Core component, allowing an unauthenticated attacker with network access via LDAP to fully compromise the directory service. The vulnerability's scope change indicates successful exploitation can impact additional connected products and systems beyond OUD itself.

Technical Analysis

CVE-2026-60360 affects Oracle Unified Directory versions 12.2.1.4.0 and 14.1.2.1.0, allowing full compromise via the LDAP protocol without authentication or user interaction (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). The scope change (S:C) designation means an attacker exploiting this flaw in OUD can pivot to impact other integrated systems that rely on it for authentication, authorization, or identity data, likely including federated SSO, application servers, and downstream services trusting OUD as an identity source. Given OUD's role as a centralized LDAP directory, compromise could enable credential harvesting, identity spoofing, and lateral movement across the enterprise. Organizations running AI agents or LLM tool-use pipelines that authenticate via LDAP/OUD-backed SSO, or that retrieve API keys, service credentials, or RAG data-source access tokens through this directory, face a direct risk of credential theft and unauthorized agent impersonation if this directory service is compromised.

Affected Systems

Oracle Unified Directory 12.2.1.4.0; Oracle Unified Directory 14.1.2.1.0; downstream applications and services integrated with OUD for LDAP-based authentication/authorization

Indicators of Compromise

  • No specific IOCs published at time of disclosure; monitor for anomalous unauthenticated LDAP bind/search requests, unexpected schema modifications, and unusual OUD process crashes or restarts

Remediation Steps

  1. 1

    Apply Oracle Critical Patch Update

    Immediately apply the vendor-released patch for CVE-2026-60360 covering OUD versions 12.2.1.4.0 and 14.1.2.1.0.

  2. 2

    Restrict LDAP network exposure

    Limit network access to OUD LDAP ports to trusted internal hosts only, using firewalls or network segmentation, until patching is complete.

  3. 3

    Enable enhanced logging and monitoring

    Turn on verbose LDAP access logging and monitor for unauthenticated bind attempts, unusual query patterns, or directory schema changes.

  4. 4

    Rotate credentials post-patch

    After patching, rotate service accounts, API keys, and stored credentials that traverse or are managed by OUD, particularly those used by automated systems and AI agents.

  5. 5

    Review downstream integrations

    Audit all applications and services trusting OUD for authentication to identify potential exposure from the scope-change impact and revalidate trust relationships.

CVE / Advisory IDs

CVE-2026-60360

Industries Most Exposed

enterprise ITfinancial servicesgovernmenthealthcaretelecommunicationstechnology

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.