Impact
Oracle Coherence suffers an unauthenticated network vulnerability that permits an attacker with TCP connectivity to compromise the system. This flaw allows the attacker to take full control of the Coherence service, leading to total loss of confidentiality, integrity, and availability. The vulnerability is rated very high with a CVSS 3.1 Base Score of 9.8, indicating a complete compromise can be achieved without initial authentication.
Affected Systems
The vulnerability applies to Oracle Coherence releases 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0, as published in Oracle’s security advisory for July 2026.
Risk and Exploitability
The exploit probability is low, with an EPSS score below 1%, and it is not currently listed in the CISA KEV catalog. Nonetheless, the high CVSS score and the fact that it is unauthenticated and reachable over the network means that once discovered, an attacker could easily gain full control of the affected services. The attack vector is a remote TCP connection that does not require authentication or privilege escalation, making it simple for any network adversary to launch a successful takeover.
OpenCVE Enrichment