External risk intelligence

Oracle Unified Directory LDAP Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-60361

The vulnerability affects Oracle Unified Directory via the LDAP protocol. While LDAP services are network-reachable, they are typically deployed within internal network segments or behind firewalls to manage directory services, rather than being exposed directly to the public internet in common deployment patterns.

Missing Authentication

Oracle Unified Directory

12.2.1.4.014.1.2.1.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in Oracle Unified Directory, a component of Oracle Fusion Middleware. This issue, exploitable over the network by a low-privileged attacker, could lead to a complete takeover of the directory and potentially impact other connected products. The high CVSS score indicates significant potential for confidentiality, integrity, and availability impacts.

  • Attackers can gain full control of directory services.
  • Important for understanding data access and system integrity.
  • Confirm relevance and exposure within our Oracle Fusion Middleware environment.

Attack Path

How an attacker could exploit the issue

An attacker with network access and low privileges can target a vulnerability in Oracle Unified Directory through the LDAP protocol. Successful exploitation could lead to a complete takeover of the directory service, potentially impacting other connected products.

  • Network access required.
  • LDAP protocol triggers vulnerability.
  • Complete takeover of the directory.

Live Threat

Current exploitation, exposure, and threat context

A low-privileged attacker with network access could exploit this vulnerability via LDAP to gain full control over Oracle Unified Directory. When supported by the advisory, this compromise could extend to other interconnected products, potentially leading to a complete takeover of the directory service.

  • Oracle Unified Directory service.
  • Via network access using LDAP.
  • Full takeover of the directory service.

Operational Fix

Recommended remediation, mitigation, and detection steps

Oracle Unified Directory owners and infrastructure teams are likely responsible for addressing this vulnerability. The first practical step is to identify all instances of Oracle Unified Directory, confirm their network reachability and business criticality, and then ascertain the accountable owner before planning remediation based on the assessed risk.

  • Identify responsible application or platform owners.
  • Verify asset exposure and business criticality.
  • Plan coordinated remediation or risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Unified Directory?

Oracle Unified Directory is a component of Oracle Fusion Middleware designed as an all-in-one directory solution. It serves as a central repository for identity and profile information, enabling organizations to manage user credentials, roles, and access permissions across diverse enterprise systems and applications.

What does CVE-2026-60361 mean for system security?

This vulnerability represents a significant security flaw that allows an attacker with basic, low-privileged access to gain full control over the Oracle Unified Directory service. Because of its nature, it can lead to a complete takeover of the directory, which may also compromise the integrity and confidentiality of other interconnected software systems relying on it.

How is the Oracle Unified Directory vulnerability triggered?

The issue is triggered when an attacker uses the LDAP protocol to interact with the target directory service over a network. It is important to note that this requires the attacker to have at least low-privileged access to the system; simply being an unauthorized user on the general network without any existing directory credentials is not described as a sufficient trigger for this specific exploit.

Is my environment at risk from this LDAP issue?

According to Halo Surface Signal, the risk depends heavily on your deployment. While the flaw is reachable via the network using LDAP, these services are typically kept behind firewalls or within internal network segments rather than on the public internet. You should care if your directory service is reachable from untrusted network zones or if you have a wide internal user base that could be leveraged by a malicious actor.

What steps should I take if I use this software?

First, conduct an inventory to locate all instances of Oracle Unified Directory within your infrastructure. Once identified, verify their current network reachability and determine which business applications rely on them. Coordinate with your infrastructure and security teams to assess the criticality of these assets and confirm who is responsible for managing them before proceeding with security updates.

References