Description
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authentication check in the HTTP interface of Oracle Coherence allows an unauthenticated attacker to send requests that can lead to full takeover of the Coherence deployment. This flaw corresponds to CWE-306: Missing Authentication for Critical Functionality. The vulnerability is executable over the network and requires no prior credentials. Compromise grants the attacker control over confidentiality, integrity, and availability of the system.

Affected Systems

Oracle Coherence for Oracle Fusion Middleware. Versions 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0 are vulnerable.

Risk and Exploitability

The CVSS base score of 9.8 signals a critical vulnerability with network access (AV:N) and no authentication required (PR:N). The EPSS score shows a very low likelihood of exploitation. Despite this, the vulnerability's lack of authentication controls makes any exposed HTTP endpoint a high-priority risk. It is not listed in the CISA KEV catalog, but the potential for complete system compromise warrants rapid remediation.

Generated by OpenCVE AI on August 2, 2026 at 23:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch for Coherence released in the security advisory.
  • Restrict network access to the Coherence service via firewall rules or a VPN, preventing untrusted users from reaching the HTTP endpoint.
  • Until a patch is available, isolate Coherence from external networks and monitor logs for abnormal HTTP traffic.

Generated by OpenCVE AI on August 2, 2026 at 23:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Complete Compromise of Oracle Coherence

Sat, 01 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Compromise in Oracle Coherence

Sun, 26 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Compromise in Oracle Coherence

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle coherence
CPEs cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle coherence
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Coherence
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T16:54:07.092Z

Reserved: 2026-07-08T15:51:40.525Z

Link: CVE-2026-60241

cve-icon Vulnrichment

Updated: 2026-07-23T16:54:01.328Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:30:07Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function