Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-06-16
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Coherence’s Centralized Third Party Jars allows an unauthenticated attacker with network access over HTTP to take full control of the Coherence service. The flaw is trivially exploitable and has a CVSS base score of 10.0, indicating complete compromise of confidentiality, integrity, and availability. Successful exploitation would result in a full takeover of the Coherence deployment, potentially affecting additional connected Oracle Fusion Middleware components due to scope changes.

Affected Systems

Affected versions are Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. The issue is reachable over standard HTTP interfaces and requires no authentication, meaning any host on the network that can reach the Coherence HTTP endpoints is vulnerable.

Risk and Exploitability

The EPSS score of less than 1% indicates a very low current exploitation probability, but the CVSS rating of 10.0 demonstrates a catastrophic impact if the vulnerability is used. Attackers could leverage the unauthenticated HTTP path to execute arbitrary code or launch denial‑of‑service attacks against the Coherence cluster. Because authentication is not required, the attack vector is considered network‑based and could be performed from any external source that can reach the exposed HTTP endpoints.

Generated by OpenCVE AI on June 17, 2026 at 20:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Coherence security patch release that addresses CVE-2026-35308, as outlined in the Oracle security advisory.
  • Configure Coherence to require authentication for all HTTP endpoints and disable anonymous access to the service.
  • Restrict external exposure of Coherence HTTP ports using network segmentation or firewall rules to limit access to trusted hosts only.

Generated by OpenCVE AI on June 17, 2026 at 20:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T15:38:34.574Z

Reserved: 2026-04-01T20:03:40.837Z

Link: CVE-2026-35308

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T23:00:05Z

Weaknesses

No weakness.