Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Coherence Core component contains a vulnerability of type improper access control (CWE-284) that, while allowing an unauthenticated attacker with network access via T3 and IIOP, is difficult to exploit. Successful exploitation would result in full takeover, impacting confidentiality, integrity, and availability. The vulnerability is represented by a CVSS 3.1 Base Score of 8.1 with a vector of AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H.

Affected Systems

Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected. The issue is limited to the Core component of the Oracle Fusion Middleware stack.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% shows that exploitation is unlikely at present. Potential attackers would need to reach the T3 or IIOP ports, which are normally exposed to the network, and initial access is difficult. Once accessed, the attacker can control the Coherence instance, compromising all data and services it manages.

Generated by OpenCVE AI on August 4, 2026 at 04:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Coherence patch issued in the July 2026 update to all affected installations.
  • Restrict unauthenticated traffic to the T3 and IIOP ports by configuring firewalls or network segmentation, allowing only trusted hosts.
  • Enforce authentication and authorization on Coherence, such as requiring client certificates or credentials for T3/IIOP connections.
  • If feasible, disable unused Coherence services or ports to reduce the attack surface.

Generated by OpenCVE AI on August 4, 2026 at 04:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated network attack via T3/IIOP enables full takeover of Oracle Coherence

Sun, 26 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated network attack via T3/IIOP enables full takeover of Oracle Coherence

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:03:24.471Z

Reserved: 2026-07-08T15:51:40.524Z

Link: CVE-2026-60222

cve-icon Vulnrichment

Updated: 2026-07-23T16:16:16.142Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:45:03Z

Weaknesses