Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Missing Authentication flaw that permits an unauthenticated attacker with TCP connectivity to an Oracle Coherence service to gain control of the service. This Missing Authentication flaw is inferred from the description, as the CVE states that no authentication is required. Successful exploitation can fully compromise the Coherence instance, leading to loss of confidentiality, integrity, and availability of all data and operations managed by Coherence. The weakness is identified as CWE‑306. No authentication is required, so any host that can reach the Coherence port can trigger the attack.

Affected Systems

Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are affected. These versions are distributed by Oracle Corporation as part of Oracle Fusion Middleware and are used in enterprise environments that rely on Coherence for distributed caching, data grid, and clustering.

Risk and Exploitability

The CVSS 3.1 Base Score of 9.8 indicates a critical vulnerability affecting confidentiality, integrity, and availability. The EPSS score of less than 1% suggests that exploitation is not widely observed at present. The vulnerability is not yet listed in the CISA KEV catalog. An attacker only needs network access to the exposed Coherence TCP port, with no credentials, to exploit the flaw, making the attack vector highly accessible to remote attackers.

Generated by OpenCVE AI on August 4, 2026 at 04:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Retrieve the official Oracle CPU July 2026 advisory and apply any security updates that address the vulnerability for the affected Coherence versions.
  • Configure firewalls or network controls to restrict inbound TCP traffic to the Coherence service port so that only trusted hosts or internal networks can reach it.
  • Until a patch is applied, isolate Coherence nodes from untrusted zones by placing them in a separate network segment, monitoring for anomalous traffic, and limiting exposed services.

Generated by OpenCVE AI on August 4, 2026 at 04:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated TCP Attacks Allow Takeover of Oracle Coherence

Tue, 28 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated TCP Attacks Allow Takeover of Oracle Coherence

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:44:35.827Z

Reserved: 2026-07-08T15:51:40.524Z

Link: CVE-2026-60234

cve-icon Vulnrichment

Updated: 2026-07-23T15:44:30.789Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function