Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The core component of Oracle Coherence is vulnerable to a low‑privilege HTTP request that allows an attacker to create, delete, or modify data stored in the service. The flaw enables unauthorized creation and deletion of objects and full read access to all data handled by Coherence, resulting in severe confidentiality and integrity compromise. The CVSS 3.1 base score of 9.6 reflects the high impact and the fact that the vulnerability is easily exploitable without additional prerequisites.

Affected Systems

Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0 are affected. The vulnerability is located in the Core component of the product and can affect systems running these releases.

Risk and Exploitability

The flaw can be triggered from any networked client that can reach the Coherence HTTP endpoint, even with a low‑privileged user account. The CVSS score of 9.6 indicates a critical rating. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, because the bug can change the scope of impact to additional products, organizations that rely on Coherence should treat this as a serious risk and act promptly. The primary attack vector is network based, via HTTP requests managed by the Coherence service.

Generated by OpenCVE AI on August 4, 2026 at 17:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Critical Patch Update released in July 2026 for all affected Coherence versions
  • Restrict network access to the Coherence HTTP port to trusted hosts only until the patch is applied
  • Disable or segregate low‑privilege accounts that can access the Coherence API to limit potential misuse

Generated by OpenCVE AI on August 4, 2026 at 17:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Enables Unauthorized Data Modification in Oracle Coherence

Sat, 01 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Enables Unauthorized Data Modification in Oracle Coherence

Tue, 28 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Vulnerability in Oracle Coherence Enables Unauthorized Data Modification
Weaknesses CWE-269

Fri, 24 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Vulnerability in Oracle Coherence Enables Unauthorized Data Modification
Weaknesses CWE-269

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T16:51:14.764Z

Reserved: 2026-07-08T15:51:40.525Z

Link: CVE-2026-60239

cve-icon Vulnrichment

Updated: 2026-07-23T16:51:11.359Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:25.717

Modified: 2026-07-24T17:14:24.940

Link: CVE-2026-60239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:45:03Z

Weaknesses