Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Core component of Oracle Coherence and permits an unauthenticated network attacker to read a subset of data exposed by the application. The flaw does not grant code execution or modify data, but it enables confidential information disclosure. The CVSS vector indicates that confidentiality is impacted while integrity and availability remain unaffected.

Affected Systems

Oracle Coherence versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are vulnerable. These versions are part of Oracle Fusion Middleware and are typically deployed in distributed caching and data grid environments. The issue affects all installations that expose the Coherence service over the network without authentication controls.

Risk and Exploitability

The base score of 5.3 and an EPSS of less than 1% suggest moderate risk and low probability of exploitation, and the vulnerability is not currently catalogued in KEV. Attackers would need network connectivity to the TCP ports used by Coherence and no special privileges. Successful exploitation yields unauthorized read access to data, which could expose sensitive information to an attacker.

Generated by OpenCVE AI on August 2, 2026 at 23:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch issued in Oracle's CPU Jul 2026 advisory for Coherence 14.1.1, 14.1.2, and 15.1.1.
  • Limit network exposure by configuring firewalls or VPNs to restrict access to the Coherence listening ports to trusted hosts only.
  • Implement application‑level authentication or access controls if not already enabled, ensuring that only privileged users can query the Coherence service.
  • Monitor server logs for unexpected or repeated connection attempts and investigate any anomalies promptly.

Generated by OpenCVE AI on August 2, 2026 at 23:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Data Disclosure via TCP in Oracle Coherence

Tue, 28 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access in Oracle Coherence via Unauthenticated Network Traffic
Weaknesses CWE-284

Fri, 24 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access in Oracle Coherence via Unauthenticated Network Traffic
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:42:28.015Z

Reserved: 2026-07-08T15:51:40.525Z

Link: CVE-2026-60237

cve-icon Vulnrichment

Updated: 2026-07-23T15:42:19.733Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:30:07Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor