Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Coherence allows an attacker to connect over TCP without authentication and take full control of the application. The flaw permits the attacker to read, modify, or delete any data and to execute arbitrary operations, resulting in complete compromise of confidentiality, integrity, and availability.

Affected Systems

Oracle Coherence product, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0.

Risk and Exploitability

The CVSS v3.1 base score of 9.8 indicates a critical severity, and the EPSS score of less than 1% shows a small but existing exploitation probability. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector, inferred from the description, is a remote TCP connection that requires no authentication and can be attempted by any external actor with network access.

Generated by OpenCVE AI on August 4, 2026 at 04:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Oracle patch for Oracle Coherence that addresses CVE‑2026‑60227, as documented in the official Oracle CPU July 2026 advisories.
  • Restart the Oracle Coherence service after applying the update to ensure the fix is active.
  • If a patch cannot be applied immediately, restrict inbound TCP traffic to the Coherence deployment using firewall rules, allowing only trusted hosts or management interfaces.

Generated by OpenCVE AI on August 4, 2026 at 04:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote TCP Exploit Allowing Oracle Coherence Takeover

Thu, 30 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote TCP Exploit Allowing Oracle Coherence Takeover

Tue, 28 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Coherence via TCP
Weaknesses CWE-200

Fri, 24 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Coherence via TCP
Weaknesses CWE-200

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:02:41.565Z

Reserved: 2026-07-08T15:51:40.524Z

Link: CVE-2026-60227

cve-icon Vulnrichment

Updated: 2026-07-23T16:24:50.398Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:45:03Z

Weaknesses