Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Coherence, a core component of Oracle Fusion Middleware, contains a vulnerability that allows an unauthenticated attacker with network access over TCP to cause unauthorized creation, deletion, or modification of critical data accessible through the system. The flaw leads to a loss of confidentiality and integrity for all data handled by the affected Coherence deployment, while availability remains unaffected. The attack requires user interaction from a third party and, due to a scope change, can have cascading effects on other surrounding products.

Affected Systems

The vulnerability affects Oracle Corporation's Oracle Coherence product in the following releases: 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Administrators of Oracle Fusion Middleware environments that incorporate any of these Coherence versions need to verify their current build and consider remediation.

Risk and Exploitability

With a CVSS v3.1 base score of 9.3, the flaw is categorized as critical, reflecting substantial confidentiality and integrity impact. The EPSS score of less than 1 % indicates that widespread exploitation is currently expected to be rare, but the presence of the flaw and high score warrant timely action. The vulnerability is not flagged in the CISA KEV catalog at this time. The likely attack path involves an unauthenticated network connection over TCP to the Coherence service, followed by exploitation steps that require the victim to interact with the system, such as triggering a specific command or configuration change. Because the CVE notes a scope change, successful exploitation could also affect other components within the application stack.

Generated by OpenCVE AI on August 4, 2026 at 04:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or update described in Oracle CPU July 2026 advisory (see https://www.oracle.com/security-alerts/cpujul2026.html).
  • Restrict inbound TCP access to Coherence nodes to a trusted set of hosts or IP ranges to reduce exposure to unauthenticated network traffic.
  • Monitor Coherence logs and network flows for anomalous actions such as unexpected data creation, deletion, or modification, and investigate any incidents promptly.

Generated by OpenCVE AI on August 4, 2026 at 04:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated TCP Attack Enables Unauthorized Data Modification in Oracle Coherence

Thu, 30 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated TCP Attack Enables Unauthorized Data Modification in Oracle Coherence

Mon, 27 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Access Enables Compromise of Oracle Coherence Data
Weaknesses CWE-200

Fri, 24 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Access Enables Compromise of Oracle Coherence Data
Weaknesses CWE-200

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:03:38.774Z

Reserved: 2026-07-08T15:51:40.524Z

Link: CVE-2026-60220

cve-icon Vulnrichment

Updated: 2026-07-23T16:16:14.644Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:45:03Z

Weaknesses