Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60361

CVE-2026-60361: Oracle Unified Directory Privilege Escalation

CVE-2026-60361 is a critical privilege escalation vulnerability in Oracle Unified Directory affecting versions 12.2.1.4.0 and 14.1.2.1.0. This article covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-60361 Overview

CVE-2026-60361 is a critical vulnerability in the Oracle Unified Directory (OUD) product of Oracle Fusion Middleware, specifically in the OUD Core component. The flaw affects supported versions 12.2.1.4.0 and 14.1.2.1.0. A low-privileged attacker with network access via Lightweight Directory Access Protocol (LDAP) can exploit the vulnerability to compromise Oracle Unified Directory. Successful exploitation results in takeover of Oracle Unified Directory and can significantly impact additional products because of scope change.

Critical Impact

Successful attacks result in complete takeover of Oracle Unified Directory with cross-scope impact on integrated identity-consuming applications.

Affected Products

  • Oracle Unified Directory 12.2.1.4.0
  • Oracle Unified Directory 14.1.2.1.0
  • Oracle Fusion Middleware deployments relying on OUD Core for directory services

Discovery Timeline

Technical Details for CVE-2026-60361

Vulnerability Analysis

The vulnerability resides in the OUD Core component of Oracle Unified Directory, Oracle's LDAP-based directory service used for identity storage, authentication, and authorization across Oracle Fusion Middleware deployments. An authenticated attacker with only low privileges can send crafted LDAP requests across the network to trigger the flaw. The attack complexity is low and requires no user interaction.

Exploitation results in full takeover of the directory server. Because Oracle Unified Directory brokers identity data for downstream applications, the scope changes and the blast radius extends beyond OUD itself. Attackers can pivot to identity-consuming Fusion Middleware services, tamper with directory entries, elevate privileges of arbitrary accounts, and read or modify sensitive identity attributes.

Root Cause

Oracle has not published root-cause details in the public advisory. The disclosure describes an LDAP-reachable defect in OUD Core that permits a low-privileged, authenticated principal to bypass expected authorization boundaries and gain administrative control over the directory instance. Refer to the Oracle Security Alert - July 2026 for vendor-issued patch details.

Attack Vector

The attack vector is network-based over LDAP or LDAPS. The attacker requires a valid low-privileged directory account, which is a common credential to obtain through phishing, credential reuse, or lateral movement inside enterprise environments. No physical access or victim interaction is required, and the vulnerability affects the Confidentiality, Integrity, and Availability of the directory and connected products.

No public proof-of-concept has been observed. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog at the time of publication.

Detection Methods for CVE-2026-60361

Indicators of Compromise

  • Anomalous LDAP bind operations from low-privileged accounts followed by administrative modify or add operations against cn=admin or cn=config subtrees.
  • Unexpected changes to directory ACIs, password policies, or replication agreements in OUD access and audit logs.
  • New or modified service accounts with elevated group memberships that were not created through standard identity governance workflows.

Detection Strategies

  • Enable and centralize OUD access, audit, and error logs, and alert on privilege changes performed by non-administrative bind DNs.
  • Baseline typical LDAP query patterns per service account and flag deviations in operation type, volume, or target subtree.
  • Correlate LDAP administrative events with downstream Fusion Middleware authentication anomalies to identify scope-change impact.

Monitoring Recommendations

  • Forward OUD logs to a SIEM or data lake and retain them long enough to support incident response investigations.
  • Monitor network traffic to LDAP ports 389 and 636 for unusual source hosts, particularly from non-application segments.
  • Track configuration drift on the OUD instance and replication topology using file integrity monitoring on config.ldif.

How to Mitigate CVE-2026-60361

Immediate Actions Required

  • Apply the July 2026 Critical Patch Update from Oracle to all Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0 instances.
  • Rotate credentials for all OUD administrative and service accounts and audit recently created or modified directory entries.
  • Restrict LDAP and LDAPS network exposure to trusted application tiers using firewall rules and network segmentation.

Patch Information

Oracle addressed CVE-2026-60361 in the July 2026 Critical Patch Update. Administrators must download and apply the fixes listed in the Oracle Security Alert - July 2026 for the affected OUD versions. Oracle does not support partial patching, so all prerequisite Fusion Middleware components must be updated to the required baseline before applying the OUD-specific fix.

Workarounds

  • Oracle has not published an official workaround; patching is the only supported remediation.
  • Enforce least privilege on directory accounts and remove unused low-privileged binds that could be abused as an initial foothold.
  • Enable strong authentication such as certificate-based binds and require LDAPS for all administrative operations until patches are deployed.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.