External risk intelligence

Oracle Unified Directory LDAP Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-60360

The vulnerability affects an LDAP-based directory service. While LDAP is a network-accessible protocol, it is typically deployed within internal network segments for identity and access management rather than being directly exposed to the public internet. While it is theoretically reachable if misconfigured, public internet exposure is not a standard deployment pattern for this type of service.

Missing Authentication

Oracle Unified Directory

12.2.1.4.014.1.2.1.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Unified Directory, a component within Oracle Fusion Middleware. This issue, if exploited, could allow an attacker to take full control of the directory service, potentially impacting other connected products due to its scope. The potential for significant data compromise and service disruption warrants attention.

  • Unauthenticated access can seize directory control.
  • Directory services manage critical access and identity.
  • Assess relevance to protect core business functions.

Attack Path

How an attacker could exploit the issue

An attacker can compromise Oracle Unified Directory by sending specially crafted network requests via LDAP. This bypasses the need for any authentication, allowing them to gain complete control over the directory service. Successful exploitation can lead to a significant impact on other connected products beyond just the directory itself.

  • No authentication required for entry.
  • Network access via LDAP triggers vulnerability.
  • Takeover of directory and connected products.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker with network access via LDAP to gain complete control over Oracle Unified Directory, potentially impacting other connected products.

  • Oracle Unified Directory systems.
  • Network access via LDAP.
  • Takeover of directory services.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners, in conjunction with infrastructure and platform teams, should take the lead in addressing this critical vulnerability within Oracle Unified Directory. The initial practical step is to inventory all instances of the affected product, determine their network accessibility and business criticality, and identify the specific accountable owner for each. Remediation planning should then be prioritized based on this risk assessment, potentially involving coordination with Oracle for patching or implementing compensating controls if immediate remediation is not feasible.

  • Application and infrastructure teams own remediation.
  • Verify product deployment and network exposure.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Unified Directory?

Oracle Unified Directory is a component of Oracle Fusion Middleware used to manage identity and access data. It functions as a directory service that stores user credentials and organizational information, serving as a foundational piece of infrastructure for authentication and authorization across enterprise applications.

What does CVE-2026-60360 mean?

CVE-2026-60360 describes a critical security flaw in the OUD Core component. It allows an attacker to bypass authentication entirely to gain full control over the directory service. Because this component sits at the heart of identity management, a takeover can allow an attacker to compromise not just the directory, but also other connected products that rely on it for security.

How is this vulnerability triggered?

The flaw is triggered when an attacker sends specially crafted requests to the system over the Lightweight Directory Access Protocol (LDAP). It is important to note that the vulnerability does not require the attacker to have valid credentials; the system fails to verify the identity of the requester before processing the malicious input.

Do I need to worry if my directory is internal?

Yes, it is still relevant. While Halo Surface Signal notes that LDAP services are typically kept within internal network segments and are not standard for public internet exposure, any attacker who gains access to your internal network can reach the service. You should evaluate the risk based on the accessibility of your directory instances to both external and internal users.

What should I do first to address this?

Your first step is to inventory all instances of Oracle Unified Directory 12.2.1.4.0 and 14.1.2.1.0 in your environment. Once identified, confirm who is responsible for each instance and assess their specific network accessibility. This information will help you prioritize patching or implementing protective controls based on the actual risk to your business operations.

References