Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an unauthenticated attacker with network access via TCP to take complete control of an Oracle Coherence instance, compromising confidentiality, integrity, and availability. The flaw resides in the core component and is identified as a weakness in authorization controls and lack of authentication. Successful exploitation results in full takeover of the Coherence service, permitting arbitrary code execution and data exfiltration.

Affected Systems

The flaw affects Oracle Coherence products distributed by Oracle Corporation in the following releases: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. These versions are listed in the Oracle Coherence product line.

Risk and Exploitability

The CVSS v3.1 base score of 9.8 marks this issue as critical. The EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation in the current window, and the vulnerability is not included in the CISA KEV catalog. Attackers only need TCP connectivity to the exposed Coherence service ports; no credentials are required. While network segmentation or firewall filtering can reduce exposure, the only definitive remedy is to apply the vendor‑issued fix.

Generated by OpenCVE AI on August 2, 2026 at 23:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Coherence patch that removes the unauthorized network access flaw.
  • Restrict inbound TCP traffic to the Coherence service ports to trusted hosts or subnet ranges only.
  • Deploy the Coherence service in an isolated network segment with strict egress controls to limit the blast radius.

Generated by OpenCVE AI on August 2, 2026 at 23:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Access Allowing Full Takeover of Oracle Coherence

Tue, 28 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover of Oracle Coherence via TCP
Weaknesses CWE-284

Fri, 24 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover of Oracle Coherence via TCP
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:51:14.077Z

Reserved: 2026-07-08T15:51:40.523Z

Link: CVE-2026-60215

cve-icon Vulnrichment

Updated: 2026-07-23T15:51:08.553Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:30:07Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function