Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Coherence, a component of Oracle Fusion Middleware, has a flaw in its Core module that lets an unauthenticated attacker send HTTP traffic to the service and seize control of it. The weakness is an Access Control issue (CWE–284) and can give the attacker confidentiality, integrity, and availability compromise. The CVSS 3.1 score of 9.8 reflects this high level of impact.

Affected Systems

Affected parties include Oracle Corporation’s Oracle Coherence product. Versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are vulnerable when the HTTP interface is reachable from external networks.

Risk and Exploitability

The severity score of 9.8 signals a critical risk, but the EPSS score of less than 1% indicates that zero‑day exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, suggesting no documented exploitation to date. The attack vector is an unauthenticated HTTP request, implying that any system exposing Coherence over the network could be targeted without prior credentialing.

Generated by OpenCVE AI on August 4, 2026 at 04:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle security update for Oracle Coherence.
  • Restrict network access to the Coherence service, for example by enforcing firewall rules or placing the service behind a reverse proxy.
  • Disable the exposed HTTP interface or enable authentication to eliminate the unauthenticated entry point.

Generated by OpenCVE AI on August 4, 2026 at 04:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Compromise of Oracle Coherence

Sat, 01 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in Oracle Coherence

Mon, 27 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in Oracle Coherence

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:02:58.580Z

Reserved: 2026-07-08T15:51:40.524Z

Link: CVE-2026-60225

cve-icon Vulnrichment

Updated: 2026-07-23T16:24:47.216Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:45:03Z

Weaknesses