CVE-2026-60360: Critical severity Oracle Oracle Unified Directory vulnerability
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60360?
CVE-2026-60360 has a critical severity rating of 10.
How do I fix CVE-2026-60360?
To fix CVE-2026-60360, upgrade to the latest supported version of Oracle Unified Directory that addresses this vulnerability.
What does CVE-2026-60360 affect?
CVE-2026-60360 affects Oracle Unified Directory in the Oracle Fusion Middleware, specifically versions 12.2.1.4.0 and 14.1.2.1.0.
Who can exploit CVE-2026-60360?
CVE-2026-60360 can be exploited by an unauthenticated attacker with network access via LDAP.
What are the potential impacts of CVE-2026-60360?
The potential impacts of CVE-2026-60360 include complete compromise of the Oracle Unified Directory, affecting confidentiality, integrity, and availability.