CVE-2026-60436: High severity Oracle Oracle Unified Directory vulnerability
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Apply mitigations that restrict LDAP network access to only trusted sources (unauthenticated attacker with network access via LDAP).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60436?
The severity of CVE-2026-60436 is rated high with a score of 7.5.
What products are affected by CVE-2026-60436?
CVS-2026-60436 affects the Oracle Unified Directory product in the Oracle Fusion Middleware version 12.2.1.4.0 and 14.1.2.1.0.
What is the risk associated with CVE-2026-60436?
CVE-2026-60436 carries a risk score of 43, indicating a significant threat.
How can I mitigate CVE-2026-60436?
To mitigate CVE-2026-60436, it is recommended to update your Oracle Unified Directory to a patched version.
Who can exploit CVE-2026-60436?
CVE-2026-60436 can be exploited by an unauthenticated attacker with network access via LDAP.