Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Coherence, part of Oracle Fusion Middleware, contains a vulnerability that permits an unauthenticated attacker with TCP network access to compromise the system. The flaw allows the attacker to take full control over the Coherence service, leading to complete loss of confidentiality, integrity, and availability of the application. This missing‑authentication weakness is identified as CWE-306 and the vulnerability is a high‑severity weakness classified as Remote Code Execution, evidenced by the CVSS vector indicating no authentication required and full impact on all security properties.

Affected Systems

The affected product is Oracle Coherence across several major releases, specifically version 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. All these versions are listed by Oracle as vulnerable and are included in the advisory linked in the references. The vulnerable component is the Core module of the Coherence product.

Risk and Exploitability

The CVSS base score of 9.8 signals critical severity, while the EPSS score of less than 1% indicates that, as of the latest data, the probability of exploitation in the wild is low. The vulnerability is not listed in the CISA KEV catalog, and the attack vector is a simple network‑based TCP connection that does not require user interaction or privileges. Because the attacker can gain unrestricted control, the risk is high for any environment that exposes Coherence to the network.

Generated by OpenCVE AI on August 4, 2026 at 17:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle Coherence patches that address CVE-2026-60230, upgrading to the fixed version published by Oracle as detailed in the Oracle advisory linked in the references.
  • If patching cannot be immediately performed, restrict TCP access to the Coherence ports so that only trusted hosts can communicate with the service, effectively blocking unauthenticated external connections.
  • Additionally, as a temporary measure, disable any unused Coherence services or shut down the Coherence cluster components that are not required for business operations to reduce the attack surface.

Generated by OpenCVE AI on August 4, 2026 at 17:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via Oracle Coherence TCP Interface

Sun, 26 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via Oracle Coherence TCP Interface

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:48:02.876Z

Reserved: 2026-07-08T15:51:40.524Z

Link: CVE-2026-60230

cve-icon Vulnrichment

Updated: 2026-07-23T15:47:53.739Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function