Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Coherence allows an unauthenticated attacker with network access via TCP to compromise the system. The weakness is a missing authentication flaw (CWE-306), enabling unauthorized access. Successful exploitation can lead to full takeover of the Coherence instance, resulting in loss of confidentiality, integrity, and availability.

Affected Systems

The affected products are Oracle Coherence versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, which are part of Oracle Fusion Middleware.

Risk and Exploitability

The EPSS score is less than 1%, indicating a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 9.8 reflects critical severity. Nevertheless, because the attack vector is remote over TCP and does not require authentication, the risk remains high. Organizations with exposed Coherence instances should treat this as a critical threat.

Generated by OpenCVE AI on August 2, 2026 at 23:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Coherence update that addresses CVE-2026-60210.
  • Restrict inbound TCP connections to the Coherence port to trusted IP ranges or virtual private networks using firewall rules.
  • Enable comprehensive monitoring and log analysis for anomalous traffic to the Coherence service to detect potential compromise.

Generated by OpenCVE AI on August 2, 2026 at 23:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Access Allows Full Compromise of Oracle Coherence

Sat, 01 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated TCP Exploit Enabling Full Takeover of Oracle Coherence

Mon, 27 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated TCP Exploit Enabling Full Takeover of Oracle Coherence

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:53:39.431Z

Reserved: 2026-07-08T15:51:40.523Z

Link: CVE-2026-60210

cve-icon Vulnrichment

Updated: 2026-07-23T15:53:35.193Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:30:07Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function