Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker who can reach the affected Oracle Coherence application over TCP may exploit a flaw in the Core component to fully compromise the Coherence service. The vulnerability allows the attacker to take control of the application, resulting in complete loss of confidentiality, integrity, and availability for the data and services managed by Coherence. It is a high‑impact remote code execution flaw.

Affected Systems

Affected products are Oracle Coherence 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. All these versions are supported by Oracle and should be updated to the latest patch series.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests that the probability of exploitation is currently very low, yet the impact of an exploit is catastrophic. The vulnerability is not listed in the CISA KEV catalog. Attackers would need only network connectivity to a listening TCP port and can exploit the flaw without authentication or user interaction.

Generated by OpenCVE AI on August 4, 2026 at 04:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s latest security patch for affected Coherence versions as announced in the July 2026 CPU.
  • Reduce exposure by configuring firewalls or network segmentation to allow TCP connections to Coherence only from trusted hosts and IP ranges.
  • Enable monitoring and logging around the Coherence service and investigate any suspicious network activity or authentication attempts without valid credentials.

Generated by OpenCVE AI on August 4, 2026 at 04:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Coherence via TCP

Tue, 28 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Coherence via TCP
Weaknesses CWE-287
CWE-94

Fri, 24 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Coherence via TCP
Weaknesses CWE-287
CWE-94

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:52:24.879Z

Reserved: 2026-07-08T15:51:40.523Z

Link: CVE-2026-60212

cve-icon Vulnrichment

Updated: 2026-07-23T15:52:20.433Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function