Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence executes to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Coherence’s Core component contains an Improper Authorization weakness that lets a low‑privileged attacker, who can reach the same physical network segment as the Coherence server, create, delete, or alter data stored in the cache. Successful exploitation can also grant the attacker read access to all data presented by Coherence services. The CVSS vector indicates high confidentiality and integrity impacts but no availability impact.

Affected Systems

Oracle Coherence from Oracle Corporation is affected in versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. No other product variants are listed.

Risk and Exploitability

The CVSS base score of 8.7 signals high severity. The EPSS score of less than 1% indicates a low likelihood of exploitation at any given time. Because the attack vector is adjacent network (AV:A), any entity on the same physical communication segment can attempt the attack without user interaction. The scope change in the vector (S:C) signals potential impacts on other products that consume Coherence. Although not listed in the CISA KEV catalog, the vulnerability’s ability to compromise critical data and broaden access to multiple applications warrants prompt action.

Generated by OpenCVE AI on August 4, 2026 at 04:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Coherence patch or upgrade released in the July 2026 CPU release to all affected installations
  • Upgrade to a newer, non‑affected major release of Oracle Coherence if patches are unavailable
  • Restrict the communication segment that hosts Coherence services so that only trusted devices can communicate with the Coherence ports

Generated by OpenCVE AI on August 4, 2026 at 04:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Oracle Coherence Enables Data Manipulation over Adjacent Network

Sat, 01 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Oracle Coherence Enables Data Manipulation over Adjacent Network

Mon, 27 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Attack on Oracle Coherence via Adjacent Network Enables Unauthorized Data Modification

Fri, 24 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Attack on Oracle Coherence via Adjacent Network Enables Unauthorized Data Modification

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Coherence executes to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:51:48.424Z

Reserved: 2026-07-08T15:51:40.523Z

Link: CVE-2026-60214

cve-icon Vulnrichment

Updated: 2026-07-23T15:51:43.549Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:45:03Z

Weaknesses