External risk intelligence

Oracle Unified Directory LDAP Takeover Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-60362

The vulnerability affects an LDAP-based directory service. While LDAP services are network-accessible and essential for identity management, they are typically deployed within internal network segments or behind firewalls to prevent unauthorized access. Direct exposure to the public internet is not a standard or recommended deployment practice for directory services.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle Unified Directory, a component of Oracle Fusion Middleware. This issue, if exploited, could allow an attacker to completely take over the directory service, potentially impacting confidentiality, integrity, and availability of the data it manages. The main concern is confirming if this technology is in use within our environment.

  • Unauthenticated attackers can gain full control.
  • Directory services are critical for identity and access.
  • Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted requests over the network to the Oracle Unified Directory. Since no authentication is required, an attacker can directly interact with the vulnerable component via LDAP. Successful exploitation allows the attacker to gain complete control of the directory service.

  • Attacker needs network access.
  • Triggered by unauthenticated LDAP requests.
  • Risk of full directory takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker with network access via LDAP could potentially compromise Oracle Unified Directory, leading to a takeover of the service. This affects the confidentiality, integrity, and availability of the directory service.

  • Directory service data and control are at risk.
  • Network-accessible LDAP could allow exposure.
  • Complete takeover of the directory service is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for Oracle Unified Directory, likely within infrastructure or platform groups, should lead the response. The first action is to identify all instances of the affected product, assess their network exposure and business criticality, and then confirm the accountable owner for each instance to prioritize remediation efforts.

  • Identify and confirm Oracle Unified Directory ownership.
  • Verify network exposure and business criticality.
  • Plan targeted remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle Unified Directory?

Oracle Unified Directory is a component of Oracle Fusion Middleware that functions as an identity management solution. It serves as a centralized directory service to store, manage, and secure user information and credentials across an organization's IT infrastructure.

What does this CVE-2026-60362 vulnerability mean?

This is a critical security flaw that allows an attacker to gain complete control over the directory service. Because the vulnerability involves the core functionality of the software, a successful attack compromises the confidentiality, integrity, and availability of the data stored within the directory.

How is the vulnerability triggered?

An attacker triggers this flaw by sending specially crafted requests over the network using the LDAP protocol. Crucially, the attacker does not need to provide any credentials or authentication to interact with the service; the system accepts the malicious input directly.

Is my environment at risk if the service is internal?

Halo Surface Signal notes that while this service requires network access, it is typically deployed in internal segments or behind firewalls. Because directory services are rarely intended for public internet access, your primary risk depends on whether the service is reachable by unauthorized parties within your network.

What should I do first to respond?

The immediate priority is to locate all instances of Oracle Unified Directory within your infrastructure. Once you have identified these systems, assess their network reachability and determine who is responsible for managing them so that remediation planning can begin.

References